NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
86538  CVE-2017-9378  BigTree CMS through 4.2.18 does not prevent a user from deleting their own account. This could have security relevance because deletion was supposed to be an admin-only action, and the admin may have other tasks (such as data backups) to complete before a user is deleted.    Medium  2017-06-12  2017-06-06  View
21258  CVE-2016-6497  main/java/org/apache/directory/groovyldap/LDAP.java in the Groovy LDAP API allows attackers to conduct LDAP entry poisoning attacks by leveraging setting returnObjFlag to true for all search methods.    Medium  2017-02-06  2017-02-02  View
86794  CVE-2016-3066  The spice-gtk widget allows remote authenticated users to obtain information from the host clipboard.    Medium  2017-06-18  2017-06-14  View
21514  CVE-2016-6910  The non-existent notification listener vulnerability was introduced in the initial Android 5.0.2 builds for the Samsung Galaxy S6 Edge devices, but the vulnerability can persist on the device even after the device has been upgraded to an Android 5.1.1 or 6.0.1 build. The vulnerable system app gives a non-existent app the ability to read the notifications from the device, which a third-party app can utilize if it uses a package name of com.samsung.android.app.portalservicewidget. This vulnerability allows an unprivileged third-party app to obtain the text of the user"s notifications, which tend to contain personal data.    4.3  Medium  2017-01-19  2016-12-27  View
21770  CVE-2016-7254  Microsoft SQL Server 2012 SP2 and 2012 SP3 does not properly perform a cast of an unspecified pointer, which allows remote authenticated users to gain privileges via unknown vectors, aka "SQL RDBMS Engine Elevation of Privilege Vulnerability."    6.5  Medium  2017-01-19  2016-11-28  View

Page 379 of 17672, showing 5 records out of 88360 total, starting on record 1891, ending on 1895

Actions