NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
84297 | CVE-2017-2420 | An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the Bluetooth component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app. | 2 | 9.3 | High | 2017-07-18 | 2017-07-11 | View | |
84553 | CVE-2017-3542 | Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Server). Supported versions that are affected are 11.1.1.8.0, 12.2.1.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Sites accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Sites. CVSS 3.0 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L). | 2 | 9 | High | 2017-07-18 | 2017-07-10 | View | |
84809 | CVE-2017-7361 | Pixie 1.0.4 allows an admin/index.php s=publish&m=static&x= XSS attack. | 2 | 4.3 | Medium | 2017-04-27 | 2017-04-04 | View | |
85065 | CVE-2017-8284 | ** DISPUTED ** The disas_insn function in target/i386/translate.c in QEMU before 2.9.0, when TCG mode without hardware acceleration is used, does not limit the instruction size, which allows local users to gain privileges by creating a modified basic block that injects code into a setuid program, as demonstrated by procmail. NOTE: the vendor has stated this bug does not violate any security guarantees QEMU makes. | 2 | 6.9 | Medium | 2017-05-27 | 2017-05-10 | View | |
85321 | CVE-2016-4892 | Cross-site scripting vulnerability in SetsucoCMS all versions allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 2 | 4.3 | Medium | 2017-05-27 | 2017-05-22 | View |
Page 16069 of 17672, showing 5 records out of 88360 total, starting on record 80341, ending on 80345