NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
21287 | CVE-2016-6581 | A HTTP/2 implementation built using any version of the Python HPACK library between v1.0.0 and v2.2.0 could be targeted for a denial of service attack, specifically a so-called "HPACK Bomb" attack. This attack occurs when an attacker inserts a header field that is exactly the size of the HPACK dynamic header table into the dynamic header table. The attacker can then send a header block that is simply repeated requests to expand that field in the dynamic table. This can lead to a gigantic compression ratio of 4,096 or better, meaning that 16kB of data can decompress to 64MB of data on the target machine. | 2 | 7.8 | High | 2017-01-30 | 2017-01-27 | View | |
21286 | CVE-2016-6580 | A HTTP/2 implementation built using any version of the Python priority library prior to version 1.2.0 could be targeted by a malicious peer by having that peer assign priority information for every possible HTTP/2 stream ID. The priority tree would happily continue to store the priority information for each stream, and would therefore allocate unbounded amounts of memory. Attempting to actually use a tree like this would also cause extremely high CPU usage to maintain the tree. | 2 | 5 | Medium | 2017-01-30 | 2017-01-27 | View | |
85656 | CVE-2016-6561 | illumos smbsrv NULL pointer dereference allows system crash. | 2 | 7.8 | High | 2017-05-08 | 2017-05-01 | View | |
21285 | CVE-2016-6550 | The U by BB&T app 1.5.4 and earlier for iOS does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | 2 | 4.3 | Medium | 2017-01-19 | 2016-11-28 | View | |
21284 | CVE-2016-6537 | AVer Information EH6108H+ devices with firmware X9.03.24.00.07l store passwords in a cleartext base64 format and require cleartext credentials in HTTP Cookie headers, which allows context-dependent attacks to obtain sensitive information by reading these strings. | 2 | 5 | Medium | 2017-01-19 | 2016-11-28 | View |
Page 1402 of 17672, showing 5 records out of 88360 total, starting on record 7006, ending on 7010