NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
83670 | CVE-2016-8232 | Document Object Model-(DOM) based cross-site scripting vulnerability in the Advanced Management Module (AMM) versions earlier than 66Z of Lenovo IBM BladeCenter HS22, HS22V, HS23, HS23E, HX5 allows an unauthenticated attacker with access to the AMM"s IP address to send a crafted URL that could inject a malicious script to access a user"s AMM data such as cookies or other session information. | 2 | 4.3 | Medium | 2017-03-18 | 2017-03-15 | View | |
83669 | CVE-2016-6485 | The __construct function in Framework/Encryption/Crypt.php in Magento 2 uses the PHP rand function to generate a random number for the initialization vector, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by guessing the value. | 2 | 5 | Medium | 2017-03-18 | 2017-03-13 | View | |
83668 | CVE-2016-5894 | IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 7.0 and 8.0 is vulnerable to information disclosure vulnerability. A local user could view a plain text password in a Unix console. IBM Reference #: 1997408. | 2 | 1.9 | Low | 2017-07-18 | 2017-07-17 | View | |
83667 | CVE-2016-5374 | NetApp Data ONTAP 9.0 and 9.1 before 9.1P1 allows remote authenticated users that own SMB-hosted data to bypass intended sharing restrictions by leveraging improper handling of the owner_rights ACL entry. | 2 | 6.5 | Medium | 2017-03-18 | 2017-03-14 | View | |
83666 | CVE-2016-1249 | The DBD::mysql module before 4.039 for Perl, when using server-side prepared statement support, allows attackers to cause a denial of service (out-of-bounds read) via vectors involving an unaligned number of placeholders in WHERE condition and output fields in SELECT expression. | 2 | 4.3 | Medium | 2017-03-18 | 2017-03-13 | View |
Page 939 of 17672, showing 5 records out of 88360 total, starting on record 4691, ending on 4695