NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
86052  CVE-2017-7952  INFOR EAM V11.0 Build 201410 has SQL injection via search fields, related to the filtervalue parameter.    6.5  Medium  2017-05-27  2017-05-24  View
21028  CVE-2016-6128  The gdImageCropThreshold function in gd_crop.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 7.0.9, allows remote attackers to cause a denial of service (application crash) via an invalid color index.    Medium  2017-01-19  2016-11-28  View
86564  CVE-2016-8741  The Apache Qpid Broker for Java can be configured to use different so called AuthenticationProviders to handle user authentication. Among the choices are the SCRAM-SHA-1 and SCRAM-SHA-256 AuthenticationProvider types. It was discovered that these AuthenticationProviders in Apache Qpid Broker for Java 6.0.x before 6.0.6 and 6.1.x before 6.1.1 prematurely terminate the SCRAM SASL negotiation if the provided user name does not exist thus allowing remote attacker to determine the existence of user accounts. The Vulnerability does not apply to AuthenticationProviders other than SCRAM-SHA-1 and SCRAM-SHA-256.    Medium  2017-06-04  2017-05-31  View
21284  CVE-2016-6537  AVer Information EH6108H+ devices with firmware X9.03.24.00.07l store passwords in a cleartext base64 format and require cleartext credentials in HTTP Cookie headers, which allows context-dependent attacks to obtain sensitive information by reading these strings.    Medium  2017-01-19  2016-11-28  View
21796  CVE-2016-7282  Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 9 through 11 and Microsoft Edge allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Microsoft Browser Information Disclosure Vulnerability."    4.3  Medium  2017-01-19  2016-12-27  View

Page 1325 of 17672, showing 5 records out of 88360 total, starting on record 6621, ending on 6625

Actions