NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
85305 | CVE-2016-4800 | The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x before 9.3.9 on Windows allows remote attackers to bypass protected resource restrictions and other security constraints via a URL with certain escaped characters, related to backslashes. | 2 | 7.5 | High | 2017-04-27 | 2017-04-25 | View | |
85304 | CVE-2016-4459 | Stack-based buffer overflow in native/mod_manager/node.c in mod_cluster 1.2.9. | 2 | 7.8 | High | 2017-04-27 | 2017-04-20 | View | |
85303 | CVE-2016-4455 | The Subscription Manager package (aka subscription-manager) before 1.17.7-1 for Candlepin uses weak permissions (755) for subscription-manager cache directories, which allows local users to obtain sensitive information by reading files in the directories. | 2 | 2.1 | Low | 2017-04-27 | 2017-04-25 | View | |
85302 | CVE-2016-4337 | SQL injection vulnerability in the mgr.login.php file in Ktools.net Photostore before 4.7.5 allows remote attackers to execute arbitrary SQL commands via the email parameter in a recover_login action. | 2 | 7.5 | High | 2017-04-27 | 2017-04-19 | View | |
85301 | CVE-2016-4068 | Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG, a different vulnerability than CVE-2015-8864. | 2 | 4.3 | Medium | 2017-04-27 | 2017-04-19 | View |
Page 612 of 17672, showing 5 records out of 88360 total, starting on record 3056, ending on 3060