NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
18133  CVE-2016-1785  The Page Loading implementation in WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles character encoding during access to cached data, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.    4.3  Medium  2017-01-19  2016-12-02  View
83669  CVE-2016-6485  The __construct function in Framework/Encryption/Crypt.php in Magento 2 uses the PHP rand function to generate a random number for the initialization vector, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by guessing the value.    Medium  2017-03-18  2017-03-13  View
18901  CVE-2016-2957  IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows remote authenticated users to obtain sensitive information by reading a stack trace in a response.    Medium  2017-01-19  2016-11-30  View
84437  CVE-2017-3204  The Go SSH library (x/crypto/ssh) by default does not verify host keys, facilitating man-in-the-middle attacks. Default behavior changed in commit e4e2799 to require explicitly registering a hostkey verification mechanism.    6.8  Medium  2017-04-27  2017-04-11  View
84693  CVE-2017-5649  Apache Geode before 1.1.1, when a cluster has enabled security by setting the security-manager property, allows remote authenticated users with CLUSTER:READ but not DATA:READ permission to access the data browser page in Pulse and consequently execute an OQL query that exposes data stored in the cluster.    Medium  2017-04-27  2017-04-11  View

Page 16158 of 17672, showing 5 records out of 88360 total, starting on record 80786, ending on 80790

Actions