NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
81957 | CVE-2016-9532 | Integer overflow in the writeBufferToSeparateStrips function in tiffcrop.c in LibTIFF before 4.0.7 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tif file. | 2 | 4.3 | Medium | 2017-02-15 | 2017-02-08 | View | |
22397 | CVE-2016-9481 | In framework/modules/core/controllers/expCommentController.php of Exponent CMS 2.4.0, content_id input is passed into showComments. The method showComments is defined in the expCommentControllercontroller with the parameter "$this->params["content_id"]" used directly in SQL. Impact is a SQL injection. | 2 | 7.5 | High | 2017-01-19 | 2016-12-02 | View | |
22396 | CVE-2016-9480 | libdwarf 2016-10-21 allows context-dependent attackers to obtain sensitive information or cause a denial of service by using the "malformed dwarf file" approach, related to a "Heap Buffer Over-read" issue affecting the dwarf_util.c component, aka DW201611-006. | 2 | 6.4 | Medium | 2017-01-19 | 2016-12-22 | View | |
22395 | CVE-2016-9479 | The "lost password" functionality in b2evolution before 6.7.9 allows remote attackers to reset arbitrary user passwords via a crafted request. | 2 | 5 | Medium | 2017-01-19 | 2016-12-27 | View | |
84039 | CVE-2016-9473 | Brave Browser iOS before 1.2.18 and Brave Browser Android 1.9.56 and earlier suffer from Full Address Bar Spoofing, allowing attackers to trick a victim by displaying a malicious page for legitimate domain names. | 2017-03-29 | 2017-03-27 | View |
Page 1038 of 17672, showing 5 records out of 88360 total, starting on record 5186, ending on 5190