NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
83751 | CVE-2017-5932 | The path autocompletion feature in Bash 4.4 allows local users to gain privileges via a crafted filename starting with a (double quote) character and a command substitution metacharacter. | 2 | 4.6 | Medium | 2017-04-27 | 2017-03-31 | View | |
85287 | CVE-2016-2104 | Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Satellite 5 allow remote attackers to inject arbitrary web script or HTML via (1) the label parameter to admin/BunchDetail.do; (2) the package_name, (3) search_subscribed_channels, or (4) channel_filter parameter to software/packages/NameOverview.do; or unspecified vectors related to (5) <input:hidden> or (6) <bean:message> tags. | 2 | 4.3 | Medium | 2017-04-27 | 2017-04-19 | View | |
83496 | CVE-2017-6949 | An issue was discovered in CHICKEN Scheme through 4.12.0. When using a nonstandard CHICKEN-specific extension to allocate an SRFI-4 vector in unmanaged memory, the vector size would be used in unsanitised form as an argument to malloc(). With an unexpected size, the impact may have been a segfault or buffer overflow. | 2 | 6.8 | Medium | 2017-04-27 | 2017-04-04 | View | |
85288 | CVE-2016-2555 | SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbitrary SQL commands via the searchFriends function to friends.inc.php. | 2 | 7.5 | High | 2017-04-27 | 2017-04-19 | View | |
84265 | CVE-2017-2387 | The Apple Music (aka com.apple.android.music) application before 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | 2 | 2.9 | Low | 2017-04-27 | 2017-04-13 | View |
Page 15813 of 17672, showing 5 records out of 88360 total, starting on record 79061, ending on 79065