NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
85305  CVE-2016-4800  The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x before 9.3.9 on Windows allows remote attackers to bypass protected resource restrictions and other security constraints via a URL with certain escaped characters, related to backslashes.    7.5  High  2017-04-27  2017-04-25  View
85304  CVE-2016-4459  Stack-based buffer overflow in native/mod_manager/node.c in mod_cluster 1.2.9.    7.8  High  2017-04-27  2017-04-20  View
85303  CVE-2016-4455  The Subscription Manager package (aka subscription-manager) before 1.17.7-1 for Candlepin uses weak permissions (755) for subscription-manager cache directories, which allows local users to obtain sensitive information by reading files in the directories.    2.1  Low  2017-04-27  2017-04-25  View
85302  CVE-2016-4337  SQL injection vulnerability in the mgr.login.php file in Ktools.net Photostore before 4.7.5 allows remote attackers to execute arbitrary SQL commands via the email parameter in a recover_login action.    7.5  High  2017-04-27  2017-04-19  View
85301  CVE-2016-4068  Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG, a different vulnerability than CVE-2015-8864.    4.3  Medium  2017-04-27  2017-04-19  View

Page 612 of 17672, showing 5 records out of 88360 total, starting on record 3056, ending on 3060

Actions