NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
83337  CVE-2017-6410  kpac/script.cpp in KDE kio before 5.32 and kdelibs before 4.14.30 calls the PAC FindProxyForURL function with a full https URL (potentially including Basic Authentication credentials, a query string, or PATH_INFO), which allows remote attackers to obtain sensitive information via a crafted PAC file.    4.3  Medium  2017-03-18  2017-03-06  View
83593  CVE-2015-8897  The SpliceImage function in MagickCore/transform.c in ImageMagick before 6.9.2-4 allows remote attackers to cause a denial of service (application crash) via a crafted png file.    4.3  Medium  2017-03-18  2017-03-17  View
83338  CVE-2017-6411  Cross Site Request Forgery (CSRF) on D-Link DSL-2730U C1 IN_1.00 devices allows remote attackers to change the DNS or firewall configuration or any password.    6.8  Medium  2017-03-18  2017-03-07  View
83594  CVE-2015-8898  The WriteImages function in magick/constitute.c in ImageMagick before 6.9.2-4 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted image file.    4.3  Medium  2017-03-18  2017-03-17  View
83339  CVE-2017-6413  The OpenID Connect Relying Party and OAuth 2.0 Resource Server (aka mod_auth_openidc) module before 2.1.6 for the Apache HTTP Server does not skip OIDC_CLAIM_ and OIDCAuthNHeader headers in an AuthType oauth20 configuration, which allows remote attackers to bypass authentication via crafted HTTP traffic.    Medium  2017-03-18  2017-03-06  View

Page 15665 of 17672, showing 5 records out of 88360 total, starting on record 78321, ending on 78325

Actions