NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
22170  CVE-2016-8740  The mod_http2 module in the Apache HTTP Server 2.4.17 through 2.4.23, when the Protocols configuration includes h2 or h2c, does not restrict request-header length, which allows remote attackers to cause a denial of service (memory consumption) via crafted CONTINUATION frames in an HTTP/2 request.    Medium  2017-01-19  2016-12-22  View
18588  CVE-2016-2355  SQL injection vulnerability in the REST API in dotCMS before 3.3.2 allows remote attackers to execute arbitrary SQL commands via the stName parameter to api/content/save/1.    7.5  High  2017-01-19  2016-12-22  View
18855  CVE-2016-2873  SQL injection vulnerability in IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.    6.5  Medium  2017-01-19  2016-12-22  View
18856  CVE-2016-2874  IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 mishandles authorization, which allows remote authenticated users to obtain sensitive information via unspecified vectors.    3.5  Low  2017-01-19  2016-12-22  View
18858  CVE-2016-2876  IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 executes unspecified processes at an incorrect privilege level, which makes it easier for remote authenticated users to obtain root access by leveraging a command-injection issue.    8.5  High  2017-01-19  2016-12-22  View

Page 3166 of 17672, showing 5 records out of 88360 total, starting on record 15826, ending on 15830

Actions