NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
83433 | CVE-2017-6573 | A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/lists/edit-list.php with the GET Parameter: id. | 2 | 6.5 | Medium | 2017-03-18 | 2017-03-13 | View | |
18153 | CVE-2016-1805 | CoreStorage in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context via a crafted app. | 2 | 9.3 | High | 2017-01-19 | 2016-11-30 | View | |
83689 | CVE-2017-1143 | IBM Kenexa LCMS Premier on Cloud 9.x and 10.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM Reference #: 1998874. | 2 | 3.5 | Low | 2017-04-27 | 2017-03-31 | View | |
18409 | CVE-2016-2112 | The bundled LDAP client library in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not recognize the "client ldap sasl wrapping" setting, which allows man-in-the-middle attackers to perform LDAP protocol-downgrade attacks by modifying the client-server data stream. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-30 | View | |
18665 | CVE-2016-2451 | codecs/on2/dec/SoftVPX.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not validate VPX output buffer sizes, which allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 27597103. | 2 | 9.3 | High | 2017-01-19 | 2016-05-10 | View |
Page 15786 of 17672, showing 5 records out of 88360 total, starting on record 78926, ending on 78930