NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
35762 | CVE-2014-8873 | A .desktop file in the Debian openjdk-7 package 7u79-2.5.5-1~deb8u1 includes a MIME type registration that is added to /etc/mailcap by mime-support, which allows remote attackers to execute arbitrary code via a JAR file. | 2 | 10 | High | 2017-01-19 | 2015-11-10 | View | |
83313 | CVE-2017-6381 | A 3rd party development library including with Drupal 8 development dependencies is vulnerable to remote code execution. This is mitigated by the default .htaccess protection against PHP execution, and the fact that Composer development dependencies aren't normal installed. You might be vulnerable to this if you are running a version of Drupal before 8.2.2. To be sure you aren't vulnerable, you can remove the <siteroot>/vendor/phpunit directory from your production deployments | 2 | 6.8 | Medium | 2017-07-18 | 2017-07-11 | View | |
76672 | CVE-2000-0429 | A backdoor password in Cart32 3.0 and earlier allows remote attackers to execute arbitrary commands. | 2 | 7.5 | High | 2017-01-05 | 2016-10-17 | View | |
82445 | CVE-2016-9244 | A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled may leak up to 31 bytes of uninitialized memory. A remote attacker may exploit this vulnerability to obtain Secure Sockets Layer (SSL) session IDs from other sessions. It is possible that other data from uninitialized memory may be returned as well. | 2 | 5 | Medium | 2017-02-28 | 2017-02-23 | View | |
22340 | CVE-2016-9272 | A Blind SQL Injection Vulnerability in Exponent CMS through 2.4.0, with the rerank array parameter, can lead to site database information disclosure and denial of service. | 2 | 6.4 | Medium | 2017-01-19 | 2016-11-29 | View |
Page 340 of 17672, showing 5 records out of 88360 total, starting on record 1696, ending on 1700