NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
83670  CVE-2016-8232  Document Object Model-(DOM) based cross-site scripting vulnerability in the Advanced Management Module (AMM) versions earlier than 66Z of Lenovo IBM BladeCenter HS22, HS22V, HS23, HS23E, HX5 allows an unauthenticated attacker with access to the AMM"s IP address to send a crafted URL that could inject a malicious script to access a user"s AMM data such as cookies or other session information.    4.3  Medium  2017-03-18  2017-03-15  View
83669  CVE-2016-6485  The __construct function in Framework/Encryption/Crypt.php in Magento 2 uses the PHP rand function to generate a random number for the initialization vector, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by guessing the value.    Medium  2017-03-18  2017-03-13  View
83668  CVE-2016-5894  IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 7.0 and 8.0 is vulnerable to information disclosure vulnerability. A local user could view a plain text password in a Unix console. IBM Reference #: 1997408.    1.9  Low  2017-07-18  2017-07-17  View
83667  CVE-2016-5374  NetApp Data ONTAP 9.0 and 9.1 before 9.1P1 allows remote authenticated users that own SMB-hosted data to bypass intended sharing restrictions by leveraging improper handling of the owner_rights ACL entry.    6.5  Medium  2017-03-18  2017-03-14  View
83666  CVE-2016-1249  The DBD::mysql module before 4.039 for Perl, when using server-side prepared statement support, allows attackers to cause a denial of service (out-of-bounds read) via vectors involving an unaligned number of placeholders in WHERE condition and output fields in SELECT expression.    4.3  Medium  2017-03-18  2017-03-13  View

Page 939 of 17672, showing 5 records out of 88360 total, starting on record 4691, ending on 4695

Actions