NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 29772 | CVE-2014-0946 | The RES Console in Rule Execution Server in IBM Operational Decision Manager 7.5 before FP3 IF37, 8.0 before MP1 FP2, and 8.5 before MP1 IF26 does not send appropriate Cache-Control HTTP headers, which allows remote attackers to obtain sensitive information by leveraging an unattended workstation. | 2 | 4.3 | Medium | 2017-01-19 | 2014-05-09 | View | |
| 18441 | CVE-2016-2168 | The req_check_access function in the mod_authz_svn module in the httpd server in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4 allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) via a crafted header in a (1) MOVE or (2) COPY request, involving an authorization check. | 2 | 4 | Medium | 2017-01-19 | 2016-11-30 | View | |
| 44613 | CVE-2012-2922 | The request_path function in includes/bootstrap.inc in Drupal 7.14 and earlier allows remote attackers to obtain sensitive information via the q[] parameter to index.php, which reveals the installation path in an error message. | 2 | 5 | Medium | 2017-01-19 | 2013-12-13 | View | |
| 47376 | CVE-2009-0027 | The request handler in JBossWS in JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP06 and 4.3 before 4.3.0.CP04 does not properly validate the resource path during a request for a WSDL file with a custom web-service endpoint, which allows remote attackers to read arbitrary XML files via a crafted request. | 2 | 5 | Medium | 2017-01-07 | 2009-03-21 | View | |
| 40138 | CVE-2013-4546 | The repository import feature in gitlab-shell before 1.7.4, as used in GitLab, allows remote authenticated users to execute arbitrary commands via the import URL. | 2 | 6.5 | Medium | 2017-01-18 | 2014-05-14 | View |
Page 3318 of 17672, showing 5 records out of 88360 total, starting on record 16586, ending on 16590