NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
17443 | CVE-2016-10088 | The sg implementation in the Linux kernel through 4.9 does not properly restrict write operations in situations where the KERNEL_DS option is set, which allows local users to read or write to arbitrary kernel memory locations or cause a denial of service (use-after-free) by leveraging access to a /dev/sg device, related to block/bsg.c and drivers/scsi/sg.c. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-9576. | 2 | 6.9 | Medium | 2017-01-19 | 2017-01-06 | View | |
83235 | CVE-2017-5666 | The free_options function in options_manager.c in mp3splt 2.6.2 allows remote attackers to cause a denial of service (invalid free and crash) via a crafted file. | 2 | 4.3 | Medium | 2017-03-18 | 2017-03-03 | View | |
17955 | CVE-2016-1605 | Directory traversal vulnerability in the ReportViewServlet servlet in the server in NetIQ Sentinel 7.4.x before 7.4.2 allows remote attackers to read arbitrary files via a PREVIEW value for the fileType field. | 2 | 6.8 | Medium | 2017-01-19 | 2016-08-01 | View | |
83491 | CVE-2017-6914 | CSRF exists in BigTree CMS 4.1.18 and 4.2.16 with the id parameter to the admin/ajax/users/delete/ page. A user can be deleted. | 2 | 5.8 | Medium | 2017-03-18 | 2017-03-16 | View | |
18211 | CVE-2016-1864 | The XSS auditor in WebKit, as used in Apple iOS before 9.3 and Safari before 9.1, does not properly handle redirects in block mode, which allows remote attackers to obtain sensitive information via a crafted URL. | 2 | 5 | Medium | 2017-01-19 | 2016-11-28 | View |
Page 1284 of 17672, showing 5 records out of 88360 total, starting on record 6416, ending on 6420