NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
84005 | CVE-2016-9266 | listmp3.c in libming 0.4.7 allows remote attackers to unspecified impact via a crafted mp3 file, which triggers an invalid left shift. | 2 | 4.3 | Medium | 2017-03-29 | 2017-03-27 | View | |
18725 | CVE-2016-2512 | The utils.http.is_safe_url function in Django before 1.8.10 and 1.9.x before 1.9.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks or possibly conduct cross-site scripting (XSS) attacks via a URL containing basic authentication, as demonstrated by http://mysite.example.com@attacker.com. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-02 | View | |
19237 | CVE-2016-3429 | Unspecified vulnerability in the Oracle Retail Xstore Point of Service component in Oracle Retail Applications 5.0, 5.5, 6.0, 6.5, 7.0, and 7.1 allows remote authenticated users to affect confidentiality and integrity via vectors related to Xstore Services. | 2 | 5.4 | Medium | 2017-01-19 | 2016-12-02 | View | |
19493 | CVE-2016-3725 | Jenkins before 2.3 and LTS before 1.651.2 allows remote authenticated users to trigger updating of update site metadata by leveraging a missing permissions check. NOTE: this issue can be combined with DNS cache poisoning to cause a denial of service (service disruption). | 2 | 5 | Medium | 2017-01-19 | 2016-07-14 | View | |
19749 | CVE-2016-4029 | WordPress before 4.5 does not consider octal and hexadecimal IP address formats when determining an intranet address, which allows remote attackers to bypass an intended SSRF protection mechanism via a crafted address. | 2 | 5 | Medium | 2017-07-18 | 2017-07-17 | View |
Page 1359 of 17672, showing 5 records out of 88360 total, starting on record 6791, ending on 6795