NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
84297  CVE-2017-2420  An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the Bluetooth component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.    9.3  High  2017-07-18  2017-07-11  View
84553  CVE-2017-3542  Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Server). Supported versions that are affected are 11.1.1.8.0, 12.2.1.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Sites accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Sites. CVSS 3.0 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L).    High  2017-07-18  2017-07-10  View
84809  CVE-2017-7361  Pixie 1.0.4 allows an admin/index.php s=publish&m=static&x= XSS attack.    4.3  Medium  2017-04-27  2017-04-04  View
85065  CVE-2017-8284  ** DISPUTED ** The disas_insn function in target/i386/translate.c in QEMU before 2.9.0, when TCG mode without hardware acceleration is used, does not limit the instruction size, which allows local users to gain privileges by creating a modified basic block that injects code into a setuid program, as demonstrated by procmail. NOTE: the vendor has stated this bug does not violate any security guarantees QEMU makes.    6.9  Medium  2017-05-27  2017-05-10  View
85321  CVE-2016-4892  Cross-site scripting vulnerability in SetsucoCMS all versions allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.    4.3  Medium  2017-05-27  2017-05-22  View

Page 16069 of 17672, showing 5 records out of 88360 total, starting on record 80341, ending on 80345

Actions