NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 22170 | CVE-2016-8740 | The mod_http2 module in the Apache HTTP Server 2.4.17 through 2.4.23, when the Protocols configuration includes h2 or h2c, does not restrict request-header length, which allows remote attackers to cause a denial of service (memory consumption) via crafted CONTINUATION frames in an HTTP/2 request. | 2 | 5 | Medium | 2017-01-19 | 2016-12-22 | View | |
| 18588 | CVE-2016-2355 | SQL injection vulnerability in the REST API in dotCMS before 3.3.2 allows remote attackers to execute arbitrary SQL commands via the stName parameter to api/content/save/1. | 2 | 7.5 | High | 2017-01-19 | 2016-12-22 | View | |
| 18855 | CVE-2016-2873 | SQL injection vulnerability in IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | 2 | 6.5 | Medium | 2017-01-19 | 2016-12-22 | View | |
| 18856 | CVE-2016-2874 | IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 mishandles authorization, which allows remote authenticated users to obtain sensitive information via unspecified vectors. | 2 | 3.5 | Low | 2017-01-19 | 2016-12-22 | View | |
| 18858 | CVE-2016-2876 | IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 executes unspecified processes at an incorrect privilege level, which makes it easier for remote authenticated users to obtain root access by leveraging a command-injection issue. | 2 | 8.5 | High | 2017-01-19 | 2016-12-22 | View |
Page 3166 of 17672, showing 5 records out of 88360 total, starting on record 15826, ending on 15830