NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
18199 | CVE-2016-1852 | Siri in Apple iOS before 9.3.2 does not block data detectors within results in the lock-screen state, which allows physically proximate attackers to obtain sensitive contact and photo information via unspecified vectors. | 2 | 2.1 | Low | 2017-01-19 | 2016-12-02 | View | |
18455 | CVE-2016-2185 | The ati_remote2_probe function in drivers/input/misc/ati_remote2.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device descriptor. | 2 | 4.9 | Medium | 2017-01-19 | 2016-11-30 | View | |
83991 | CVE-2016-9125 | Revive Adserver before 3.2.3 suffers from session fixation, by allowing arbitrary session identifiers to be forced and, at the same time, by not invalidating the existing session upon a successful authentication. Under some circumstances, that could have been an opportunity for an attacker to steal an authenticated session. | 2 | 7.5 | High | 2017-03-29 | 2017-03-29 | View | |
18711 | CVE-2016-2498 | The Qualcomm Wi-Fi driver in Android before 2016-06-01 on Nexus 7 (2013) devices allows attackers to bypass intended data-access restrictions via a crafted application, aka internal bug 27777162. | 2 | 4.3 | Medium | 2017-01-19 | 2016-06-14 | View | |
18967 | CVE-2016-3094 | PlainSaslServer.java in Apache Qpid Java before 6.0.3, when the broker is configured to allow plaintext passwords, allows remote attackers to cause a denial of service (broker termination) via a crafted authentication attempt, which triggers an uncaught exception. | 2 | 4.3 | Medium | 2017-01-19 | 2016-11-29 | View |
Page 1402 of 17672, showing 5 records out of 88360 total, starting on record 7006, ending on 7010