NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 20710 | CVE-2016-5460 | Unspecified vulnerability in the Siebel Core - Server Framework component in Oracle Siebel CRM 8.1.1, 8.2.2, IP2014, IP2015, and IP2016 allows remote attackers to affect confidentiality via vectors related to Services, a different vulnerability than CVE-2016-3450 and CVE-2016-5466. | 2 | 4.3 | Medium | 2017-01-19 | 2016-11-28 | View | |
| 20966 | CVE-2016-5833 | Cross-site scripting (XSS) vulnerability in the column_title function in wp-admin/includes/class-wp-media-list-table.php in WordPress before 4.5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted attachment name, a different vulnerability than CVE-2016-5834. | 2 | 4.3 | Medium | 2017-01-19 | 2016-11-29 | View | |
| 21222 | CVE-2016-6448 | A vulnerability in the Session Description Protocol (SDP) parser of Cisco Meeting Server could allow an unauthenticated, remote attacker to execute arbitrary code on an affected system. This vulnerability affects the following products: Cisco Meeting Server releases prior to Release 2.0.3, Acano Server releases 1.9.x prior to Release 1.9.5, Acano Server releases 1.8.x prior to Release 1.8.17. More Information: CSCva76004. Known Affected Releases: 1.8.x 1.92.0. | 2 | 7.5 | High | 2017-01-19 | 2016-11-28 | View | |
| 21478 | CVE-2016-6842 | An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. Setting the user"s name to JS code makes that code execute when selecting that user"s "Templates" folder from OX Documents settings. This requires the folder to be shared to the victim. Malicious script code can be executed within a user"s context. This can lead to session hijacking or triggering unwanted actions via the web interface (sending mail, deleting data etc.). | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-16 | View | |
| 21734 | CVE-2016-7218 | Bowser.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows local users to obtain sensitive information via a crafted application, aka "Windows Bowser.sys Information Disclosure Vulnerability." | 2 | 1.9 | Low | 2017-01-19 | 2016-11-28 | View |
Page 14796 of 17672, showing 5 records out of 88360 total, starting on record 73976, ending on 73980