NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
21644 | CVE-2016-7099 | The tls.checkServerIdentity function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 does not properly handle wildcards in name fields of X.509 certificates, which allows man-in-the-middle attackers to spoof servers via a crafted certificate. | 2 | 4.3 | Medium | 2017-01-19 | 2016-10-12 | View | |
21643 | CVE-2016-7098 | Race condition in wget 1.17 and earlier, when used in recursive or mirroring mode to download a single file, might allow remote servers to bypass intended access list restrictions by keeping an HTTP connection open. | 2 | 6.8 | Medium | 2017-01-19 | 2017-01-06 | View | |
21642 | CVE-2016-7097 | The filesystem implementation in the Linux kernel through 4.8.2 preserves the setgid bit during a setxattr call, which allows local users to gain group privileges by leveraging the existence of a setgid program with restrictions on execute permissions. | 2 | 3.6 | Low | 2017-07-18 | 2017-07-10 | View | |
21641 | CVE-2016-7095 | Exponent CMS before 2.3.9 is vulnerable to an attacker uploading a malicious script file using redirection to place the script in an unprotected folder, one allowing script execution. | 2 | 7.5 | High | 2017-01-19 | 2016-11-28 | View | |
21640 | CVE-2016-7094 | Buffer overflow in Xen 4.7.x and earlier allows local x86 HVM guest OS administrators on guests running with shadow paging to cause a denial of service via a pagetable update. | 2 | 1.5 | Low | 2017-01-19 | 2017-01-06 | View |
Page 1321 of 17672, showing 5 records out of 88360 total, starting on record 6601, ending on 6605