NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
88349 | CVE-2016-10244 | The parse_charstrings function in type1/t1load.c in FreeType 2 before 2.7 does not ensure that a font contains a glyph name, which allows remote attackers to cause a denial of service (heap-based buffer over-read) or possibly have unspecified other impact via a crafted file. | 2 | 6.8 | Medium | 2017-07-18 | 2017-07-11 | View | |
23069 | CVE-2015-0605 | The uuencode inspection engine in Cisco AsyncOS on Cisco Email Security Appliance (ESA) devices 8.5 and earlier allows remote attackers to bypass intended content restrictions via a crafted e-mail attachment with uuencode encoding, aka Bug ID CSCzv54343. | 2 | 4.3 | Medium | 2017-01-19 | 2015-02-19 | View | |
23325 | CVE-2015-0900 | Cross-site scripting (XSS) vulnerability in schedule.cgi in Nishishi Factory Fumy Teacher"s Schedule Board 1.10 through 2.21 allows remote attackers to inject arbitrary web script or HTML via a crafted URL. | 2 | 4.3 | Medium | 2017-01-19 | 2015-03-31 | View | |
23837 | CVE-2015-1564 | Cross-site scripting (XSS) vulnerability in style-underground/search in Plain Black WebGUI 7.10.29 and earlier allows remote attackers to inject arbitrary web script or HTML via the Search field. | 2 | 4.3 | Medium | 2017-01-19 | 2015-02-09 | View | |
24093 | CVE-2015-1889 | The Big SQL component in IBM InfoSphere BigInsights 3.0 through 3.0.0.2 allows remote authenticated users to bypass intended HDFS data-access restrictions via (1) a crafted CREATE HADOOP TABLE statement referencing the data of an arbitrary user or (2) an import of a certain Hive table definition with the HCAT_SYNC_OBJECTS procedure. | 2 | 6.5 | Medium | 2017-01-19 | 2017-01-02 | View |
Page 1064 of 17672, showing 5 records out of 88360 total, starting on record 5316, ending on 5320