NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
72720  CVE-2004-2343  ** DISPUTED ** Apache HTTP Server 2.0.47 and earlier allows local users to bypass .htaccess file restrictions, as specified in httpd.conf with directives such as Deny From All, by using an ErrorDocument directive. NOTE: the vendor has disputed this issue, since the .htaccess mechanism is only intended to restrict external web access, and a local user already has the privileges to perform the same operations without using ErrorDocument.    7.2  High  2017-07-18  2017-07-10  View
36690  CVE-2013-0346  ** DISPUTED ** Apache Tomcat 7.x uses world-readable permissions for the log directory and its files, which might allow local users to obtain sensitive information by reading a file. NOTE: One Tomcat distributor has stated "The tomcat log directory does not contain any sensitive information."    2.1  Low  2017-01-18  2014-02-18  View
39639  CVE-2013-3926  ** DISPUTED ** Atlassian Crowd 2.6.3 allows remote attackers to execute arbitrary commands via unspecified vectors related to a "symmetric backdoor." NOTE: as of 20130704, the vendor could not reproduce the issue, stating "We"ve been unable to substantiate the existence of [CVE-2013-3926]. The author of the article has not contacted Atlassian and has provided no detail, making it difficult to validate the claim... If we can confirm that there is a vulnerability, a patch will be issued."    7.5  High  2017-01-18  2013-10-04  View
84831  CVE-2017-7397  ** DISPUTED ** BackBox Linux 4.6 allows remote attackers to cause a denial of service (ksoftirqd CPU consumption) via a flood of packets with Martian source IP addresses (as defined in RFC 1812 section 5.3.7). This product enables net.ipv4.conf.all.log_martians by default. NOTE: the vendor reports It has been proved that this vulnerability has no foundation and it is totally fake and based on false assumptions.    Medium  2017-04-27  2017-04-11  View
86689  CVE-2017-9443  ** DISPUTED ** BigTree CMS through 4.2.18 allows remote authenticated users to conduct SQL injection attacks via a crafted tables object in manifest.json in an uploaded package. This issue exists in coreadminmodulesdeveloperextensionsinstallprocess.php and coreadminmodulesdeveloperpackagesinstallprocess.php. NOTE: the vendor states You must implicitly trust any package or extension you install as they all have the ability to write PHP files.    6.5  Medium  2017-06-12  2017-06-09  View

Page 71 of 17672, showing 5 records out of 88360 total, starting on record 351, ending on 355

Actions