NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
18133 | CVE-2016-1785 | The Page Loading implementation in WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles character encoding during access to cached data, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-02 | View | |
83669 | CVE-2016-6485 | The __construct function in Framework/Encryption/Crypt.php in Magento 2 uses the PHP rand function to generate a random number for the initialization vector, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by guessing the value. | 2 | 5 | Medium | 2017-03-18 | 2017-03-13 | View | |
18901 | CVE-2016-2957 | IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows remote authenticated users to obtain sensitive information by reading a stack trace in a response. | 2 | 4 | Medium | 2017-01-19 | 2016-11-30 | View | |
84437 | CVE-2017-3204 | The Go SSH library (x/crypto/ssh) by default does not verify host keys, facilitating man-in-the-middle attacks. Default behavior changed in commit e4e2799 to require explicitly registering a hostkey verification mechanism. | 2 | 6.8 | Medium | 2017-04-27 | 2017-04-11 | View | |
84693 | CVE-2017-5649 | Apache Geode before 1.1.1, when a cluster has enabled security by setting the security-manager property, allows remote authenticated users with CLUSTER:READ but not DATA:READ permission to access the data browser page in Pulse and consequently execute an OQL query that exposes data stored in the cluster. | 2 | 4 | Medium | 2017-04-27 | 2017-04-11 | View |
Page 16158 of 17672, showing 5 records out of 88360 total, starting on record 80786, ending on 80790