NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
88349  CVE-2016-10244  The parse_charstrings function in type1/t1load.c in FreeType 2 before 2.7 does not ensure that a font contains a glyph name, which allows remote attackers to cause a denial of service (heap-based buffer over-read) or possibly have unspecified other impact via a crafted file.    6.8  Medium  2017-07-18  2017-07-11  View
23069  CVE-2015-0605  The uuencode inspection engine in Cisco AsyncOS on Cisco Email Security Appliance (ESA) devices 8.5 and earlier allows remote attackers to bypass intended content restrictions via a crafted e-mail attachment with uuencode encoding, aka Bug ID CSCzv54343.    4.3  Medium  2017-01-19  2015-02-19  View
23325  CVE-2015-0900  Cross-site scripting (XSS) vulnerability in schedule.cgi in Nishishi Factory Fumy Teacher"s Schedule Board 1.10 through 2.21 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.    4.3  Medium  2017-01-19  2015-03-31  View
23837  CVE-2015-1564  Cross-site scripting (XSS) vulnerability in style-underground/search in Plain Black WebGUI 7.10.29 and earlier allows remote attackers to inject arbitrary web script or HTML via the Search field.    4.3  Medium  2017-01-19  2015-02-09  View
24093  CVE-2015-1889  The Big SQL component in IBM InfoSphere BigInsights 3.0 through 3.0.0.2 allows remote authenticated users to bypass intended HDFS data-access restrictions via (1) a crafted CREATE HADOOP TABLE statement referencing the data of an arbitrary user or (2) an import of a certain Hive table definition with the HCAT_SYNC_OBJECTS procedure.    6.5  Medium  2017-01-19  2017-01-02  View

Page 1064 of 17672, showing 5 records out of 88360 total, starting on record 5316, ending on 5320

Actions