NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
21951 | CVE-2016-7907 | The imx_fec_do_tx function in hw/net/imx_fec.c in QEMU (aka Quick Emulator) does not properly limit the buffer descriptor count when transmitting packets, which allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via vectors involving a buffer descriptor with a length of 0 and crafted values in bd.flags. | 2 | 2.1 | Low | 2017-01-19 | 2017-01-06 | View | |
21950 | CVE-2016-7906 | magick/attribute.c in ImageMagick 7.0.3-2 allows remote attackers to cause a denial of service (use-after-free) via a crafted file. | 2 | 4.3 | Medium | 2017-01-30 | 2017-01-23 | View | |
21949 | CVE-2016-7905 | The read_gab2_sub function in libavformat/avidec.c in FFmpeg before 3.1.4 allows remote attackers to cause a denial of service (NULL pointer used) via a crafted AVI file. | 2 | 4.3 | Medium | 2017-01-19 | 2017-01-03 | View | |
21948 | CVE-2016-7904 | Cross-site request forgery (CSRF) vulnerability in CMS Made Simple before 2.1.6 allows remote attackers to hijack the authentication of administrators for requests that create accounts via an admin/adduser.php request. | 2 | 6 | Medium | 2017-01-30 | 2017-01-27 | View | |
21947 | CVE-2016-7903 | Dotclear before 2.10.3, when the Host header is not part of the web server routing process, allows remote attackers to modify the password reset address link via the HTTP Host header. | 2 | 4.3 | Medium | 2017-01-19 | 2017-01-06 | View |
Page 1222 of 17672, showing 5 records out of 88360 total, starting on record 6106, ending on 6110