NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 86192 | CVE-2017-9068 | In MODX Revolution before 2.5.7, an attacker is able to trigger Reflected XSS by injecting payloads into several fields on the setup page, as demonstrated by the database_type parameter. | 2 | 4.3 | Medium | 2017-06-03 | 2017-05-30 | View | |
| 86448 | CVE-2016-9250 | In F5 BIG-IP 11.2.1, 11.4.0 through 11.6.1, and 12.0.0 through 12.1.2, an unauthenticated user with access to the control plane may be able to delete arbitrary files through an undisclosed mechanism. | 2 | 5 | Medium | 2017-05-27 | 2017-05-19 | View | |
| 86704 | CVE-2017-9474 | In ytnef 1.9.2, the DecompressRTF function in lib/ytnef.c allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file. | 2 | 4.3 | Medium | 2017-06-12 | 2017-06-09 | View | |
| 21680 | CVE-2016-7153 | The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack. | 2 | 5 | Medium | 2017-01-19 | 2016-11-28 | View | |
| 87216 | CVE-2016-5391 | libreswan before 3.18 allows remote attackers to cause a denial of service (NULL pointer dereference and pluto daemon restart). | 2 | 5 | Medium | 2017-06-23 | 2017-06-21 | View |
Page 14851 of 17672, showing 5 records out of 88360 total, starting on record 74251, ending on 74255