NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
83310  CVE-2017-6370  TYPO3 7.6.15 sends an http request to an index.php?loginProvider URI in cases with an https Referer, which allows remote attackers to obtain sensitive cleartext information by sniffing the network and reading the userident and username fields.    Medium  2017-03-29  2017-03-27  View
83822  CVE-2017-7206  The ff_h2645_extract_rbsp function in libavcodec in libav 9.21 allows remote attackers to cause a denial of service (heap-based buffer over-read) or obtain sensitive information from process memory via a crafted h264 video file.    5.8  Medium  2017-03-29  2017-03-23  View
84334  CVE-2017-2457  An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves the WebKit component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.    6.8  Medium  2017-07-18  2017-07-11  View
84590  CVE-2017-3581  Vulnerability in the Automatic Service Request (ASR) component of Oracle Support Tools (subcomponent: ASR Manager). The supported version that is affected is Prior to 5.7. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Automatic Service Request (ASR) executes to compromise Automatic Service Request (ASR). Successful attacks of this vulnerability can result in takeover of Automatic Service Request (ASR). CVSS 3.0 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).    4.6  Medium  2017-05-07  2017-05-02  View
84846  CVE-2017-7446  HelpDEZk 1.1.1 has CSRF in admin/home#/person/ with an impact of obtaining admin privileges.    6.8  Medium  2017-04-27  2017-04-10  View

Page 1086 of 17672, showing 5 records out of 88360 total, starting on record 5426, ending on 5430

Actions