NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
22283 | CVE-2016-9135 | Exponent CMS 2.3.9 suffers from a SQL injection vulnerability in "/framework/modules/help/controllers/helpController.php" affecting the version parameter. Impact is Information Disclosure. | 2 | 5 | Medium | 2017-01-19 | 2016-11-29 | View | |
87819 | CVE-2017-11193 | Pulse Connect Secure 8.3R1 has CSRF in diag.cgi. In the panel, the diag.cgi file is responsible for running commands such as ping, ping6, traceroute, traceroute6, nslookup, arp, and Portprobe. These functions do not have any protections against CSRF. That can allow an attacker to run these commands against any IP if they can get an admin to visit their malicious CSRF page. | 2 | 6.8 | Medium | 2017-07-18 | 2017-07-17 | View | |
23307 | CVE-2015-0881 | CRLF injection vulnerability in Squid before 3.1.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted header in a response. | 2 | 4.3 | Medium | 2017-01-19 | 2015-03-04 | View | |
23563 | CVE-2015-1194 | pax 1:20140703 allows remote attackers to write to arbitrary files via a symlink attack in an archive. | 2 | 4.3 | Medium | 2017-01-19 | 2015-01-23 | View | |
24075 | CVE-2015-1859 | Multiple buffer overflows in plugins/imageformats/ico/qicohandler.cpp in the QtBase module in Qt before 4.8.7 and 5.x before 5.4.2 allow remote attackers to cause a denial of service (segmentation fault and crash) and possibly execute arbitrary code via a crafted ICO image. | 2 | 6.8 | Medium | 2017-01-19 | 2016-12-30 | View |
Page 415 of 17672, showing 5 records out of 88360 total, starting on record 2071, ending on 2075