NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 82118 | CVE-2016-9448 | The TIFFFetchNormalTag function in LibTiff 4.0.6 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) by setting the tags TIFF_SETGET_C16ASCII or TIFF_SETGET_C32_ASCII to values that access 0-byte arrays. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-9297. | 2 | 5 | Medium | 2017-02-08 | 2017-02-07 | View | |
| 17094 | CVE-2016-0703 | The get_client_master_key function in s2_srvr.c in the SSLv2 implementation in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a accepts a nonzero CLIENT-MASTER-KEY CLEAR-KEY-LENGTH value for an arbitrary cipher, which allows man-in-the-middle attackers to determine the MASTER-KEY value and decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, a related issue to CVE-2016-0800. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-27 | View | |
| 82630 | CVE-2017-6301 | An issue was discovered in ytnef before 1.9.1. This is related to a patch described as 4 of 9. Out of Bounds Reads. | 2 | 6.8 | Medium | 2017-03-18 | 2017-03-01 | View | |
| 82886 | CVE-2016-5028 | The print_frame_inst_bytes function in libdwarf before 20160923 allows remote attackers to cause a denial of service (NULL pointer dereference) via an object file with empty bss-like sections. | 2 | 4.3 | Medium | 2017-02-28 | 2017-02-22 | View | |
| 17606 | CVE-2016-1149 | Cross-site scripting (XSS) vulnerability in Cybozu Office 9.0.0 through 10.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-7795, CVE-2015-7796, CVE-2015-7797, CVE-2015-7798, and CVE-2016-1150. | 2 | 4.3 | Medium | 2017-01-19 | 2016-02-22 | View |
Page 15624 of 17672, showing 5 records out of 88360 total, starting on record 78116, ending on 78120