NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
17916  CVE-2016-1523  The SillMap::readFace function in FeatureMap.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, mishandles a return value, which allows remote attackers to cause a denial of service (missing initialization, NULL pointer dereference, and application crash) via a crafted Graphite smart font.    4.3  Medium  2017-01-19  2016-12-05  View
17917  CVE-2016-1524  Multiple unrestricted file upload vulnerabilities in NETGEAR Management System NMS300 1.5.0.11 and earlier allow remote attackers to execute arbitrary Java code by using (1) fileUpload.do or (2) lib-1.0/external/flash/fileUpload.do to upload a JSP file, and then accessing it via a direct request for a /null URI.    8.3  High  2017-01-19  2016-12-05  View
17918  CVE-2016-1525  Directory traversal vulnerability in data/config/image.do in NETGEAR Management System NMS300 1.5.0.11 and earlier allows remote authenticated users to read arbitrary files via a .. (dot dot) in the realName parameter.    7.8  High  2017-01-19  2016-12-05  View
17919  CVE-2016-1526  The TtfUtil:LocaLookup function in TtfUtil.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, incorrectly validates a size value, which allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and application crash) via a crafted Graphite smart font.    5.8  Medium  2017-01-19  2016-12-05  View
17920  CVE-2016-1531  Exim before 4.86.2, when installed setuid root, allows local users to gain privileges via the perl_startup argument.    6.9  Medium  2017-01-19  2016-12-02  View

Page 15484 of 17672, showing 5 records out of 88360 total, starting on record 77416, ending on 77420

Actions