NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
85067  CVE-2017-8288  gnome-shell 3.22 through 3.24.1 mishandles extensions that fail to reload, which can lead to leaving extensions enabled in the lock screen. With these extensions, a bystander could launch applications (but not interact with them), see information from the extensions (e.g., what applications you have opened or what music you were playing), or even execute arbitrary commands. It all depends on what extensions a user has enabled. The problem is caused by lack of exception handling in js/ui/extensionSystem.js.    6.8  Medium  2017-05-27  2017-05-10  View
85323  CVE-2016-4894  SetsucoCMS all versions allows remote attackers to cause a denial of service via unspecified vectors.    Medium  2017-05-27  2017-05-22  View
85579  CVE-2017-8458  Brave 0.12.4 has a URI Obfuscation issue in which a string such as https://safe.example.com@unsafe.example.com/ is displayed without a clear UI indication that it is not a resource on the safe.example.com web site.    4.3  Medium  2017-05-27  2017-05-12  View
85835  CVE-2017-2504  An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS before 10.2.1 is affected. The issue involves the WebKit component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site that improperly interacts with WebKit Editor commands.    4.3  Medium  2017-07-18  2017-07-07  View
86091  CVE-2017-8845  The lzo1x_decompress function in lzo1x_d.ch in LZO 2.08, as used in lrzip 0.631, allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted archive.    4.3  Medium  2017-05-27  2017-05-18  View

Page 16085 of 17672, showing 5 records out of 88360 total, starting on record 80421, ending on 80425

Actions