NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
86356  CVE-2016-2165  The Loggregator Traffic Controller endpoints in cf-release v231 and lower, Pivotal Elastic Runtime versions prior to 1.5.19 AND 1.6.x versions prior to 1.6.20 are not cleansing request URL paths when they are invalid and are returning them in the 404 response. This could allow malicious scripts to be written directly into the 404 response.    4.3  Medium  2017-06-12  2017-06-07  View
86612  CVE-2017-4905  VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-201703403-SG, 6.0 U1 without patch ESXi600-201703402-SG, 5.5 without patch ESXi550-201703401-SG; Workstation Pro / Player 12.x prior to 12.5.5; and Fusion Pro / Fusion 8.x prior to 8.5.6 have uninitialized memory usage. This issue may lead to an information leak.    2.1  Low  2017-07-18  2017-07-11  View
86868  CVE-2016-9991  IBM Sterling Order Management 9.2 through 9.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 121314.    Medium  2017-06-18  2017-06-14  View
87124  CVE-2017-9583  The Charlevoix State Bank by Charlevoix State Bank app 3.0.1 -- aka charlevoix-state-bank/id1128963717 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.    4.3  Medium  2017-07-18  2017-06-28  View
87380  CVE-2017-7416  ntopng before 3.0 allows XSS because GET and POST parameters are improperly validated.    4.3  Medium  2017-07-18  2017-06-29  View

Page 16153 of 17672, showing 5 records out of 88360 total, starting on record 80761, ending on 80765

Actions