NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
85574 | CVE-2017-8419 | LAME through 3.99.5 relies on the signed integer data type for values in a WAV or AIFF header, which allows remote attackers to cause a denial of service (stack-based buffer overflow or heap-based buffer overflow) or possibly have unspecified other impact via a crafted file, as demonstrated by mishandling of num_channels. | 2 | 6.8 | Medium | 2017-05-27 | 2017-05-15 | View | |
86086 | CVE-2017-8832 | Allen Disk 1.6 has XSS in the id parameter to downfile.php. | 2 | 4.3 | Medium | 2017-05-27 | 2017-05-16 | View | |
85575 | CVE-2017-8421 | The function coff_set_alignment_hook in coffcode.h in Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has a memory leak vulnerability which can cause memory exhaustion in objdump via a crafted PE file. Additional validation in dump_relocs_in_section in objdump.c can resolve this. | 2 | 7.1 | High | 2017-05-27 | 2017-05-12 | View | |
85064 | CVE-2017-8283 | dpkg-source in dpkg 1.3.0 through 1.18.23 is able to use a non-GNU patch program and does not offer a protection mechanism for blank-indented diff hunks, which allows remote attackers to conduct directory traversal attacks via a crafted Debian source package, as demonstrated by use of dpkg-source on NetBSD. | 2 | 7.5 | High | 2017-05-27 | 2017-05-10 | View | |
85320 | CVE-2016-4891 | Cross-site request forgery (CSRF) vulnerability in SetsucoCMS all versions allows remote attackers to hijack the authentication of an administrator to change settings via unspecified vectors. | 2 | 6.8 | Medium | 2017-05-27 | 2017-05-22 | View |
Page 16014 of 17672, showing 5 records out of 88360 total, starting on record 80066, ending on 80070