NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
17676 | CVE-2016-1248 | vim before patch 8.0.0056 does not properly validate values for the "filetype", "syntax" and "keymap" options, which may result in the execution of arbitrary code if a file with a specially crafted modeline is opened. | 2 | 6.8 | Medium | 2017-01-19 | 2017-01-17 | View | |
83212 | CVE-2017-5526 | Memory leak in hw/audio/es1370.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption and QEMU process crash) via a large number of device unplug operations. | 2 | 4.9 | Medium | 2017-03-18 | 2017-03-17 | View | |
17932 | CVE-2016-1565 | Cross-site scripting (XSS) vulnerability in the Field Group module 7.x-1.x before 7.x-1.5 for Drupal allows remote authenticated users with permission to configure field display settings to inject arbitrary web script or HTML via an element attribute. | 2 | 3.5 | Low | 2017-01-19 | 2016-01-11 | View | |
83468 | CVE-2017-6842 | The ColorChanger::GetColorFromStack function in colorchanger.cpp in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file. | 2 | 4.3 | Medium | 2017-03-18 | 2017-03-16 | View | |
18188 | CVE-2016-1840 | Heap-based buffer overflow in the xmlFAParsePosCharGroup function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted XML document. | 2 | 6.8 | Medium | 2017-01-19 | 2016-12-27 | View |
Page 1194 of 17672, showing 5 records out of 88360 total, starting on record 5966, ending on 5970