NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
22511  CVE-2016-9891  Cross-site scripting (XSS) vulnerability in admin/media.php and admin/media_item.php in Dotclear before 2.11 allows remote authenticated users to inject arbitrary web script or HTML via the upfiletitle or media_title parameter (aka the media title).    3.5  Low  2017-01-19  2017-01-03  View
31217  CVE-2014-2899  wolfSSL CyaSSL before 2.9.4 allows remote attackers to cause a denial of service (NULL pointer dereference) via (1) a request for the peer certificate when a certificate parsing failure occurs or (2) a client_key_exchange message when the ephemeral key is not found.    Medium  2017-01-19  2017-01-03  View
31218  CVE-2014-2900  wolfSSL CyaSSL before 2.9.4 does not properly validate X.509 certificates with unknown critical extensions, which allows man-in-the-middle attackers to spoof servers via crafted X.509 certificate.    5.8  Medium  2017-01-19  2017-01-03  View
22516  CVE-2016-9913  Memory leak in the v9fs_device_unrealize_common function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause a denial of service (host memory consumption and possibly QEMU process crash) via vectors involving the order of resource cleanup.    4.9  Medium  2017-01-19  2017-01-03  View
22517  CVE-2016-9914  Memory leak in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause a denial of service (host memory consumption and possibly QEMU process crash) by leveraging a missing cleanup operation in FileOperations.    4.9  Medium  2017-01-19  2017-01-03  View

Page 14939 of 17672, showing 5 records out of 88360 total, starting on record 74691, ending on 74695

Actions