NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
85067 | CVE-2017-8288 | gnome-shell 3.22 through 3.24.1 mishandles extensions that fail to reload, which can lead to leaving extensions enabled in the lock screen. With these extensions, a bystander could launch applications (but not interact with them), see information from the extensions (e.g., what applications you have opened or what music you were playing), or even execute arbitrary commands. It all depends on what extensions a user has enabled. The problem is caused by lack of exception handling in js/ui/extensionSystem.js. | 2 | 6.8 | Medium | 2017-05-27 | 2017-05-10 | View | |
85323 | CVE-2016-4894 | SetsucoCMS all versions allows remote attackers to cause a denial of service via unspecified vectors. | 2 | 5 | Medium | 2017-05-27 | 2017-05-22 | View | |
85579 | CVE-2017-8458 | Brave 0.12.4 has a URI Obfuscation issue in which a string such as https://safe.example.com@unsafe.example.com/ is displayed without a clear UI indication that it is not a resource on the safe.example.com web site. | 2 | 4.3 | Medium | 2017-05-27 | 2017-05-12 | View | |
85835 | CVE-2017-2504 | An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS before 10.2.1 is affected. The issue involves the WebKit component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site that improperly interacts with WebKit Editor commands. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-07 | View | |
86091 | CVE-2017-8845 | The lzo1x_decompress function in lzo1x_d.ch in LZO 2.08, as used in lrzip 0.631, allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted archive. | 2 | 4.3 | Medium | 2017-05-27 | 2017-05-18 | View |
Page 16085 of 17672, showing 5 records out of 88360 total, starting on record 80421, ending on 80425