NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
85065  CVE-2017-8284  ** DISPUTED ** The disas_insn function in target/i386/translate.c in QEMU before 2.9.0, when TCG mode without hardware acceleration is used, does not limit the instruction size, which allows local users to gain privileges by creating a modified basic block that injects code into a setuid program, as demonstrated by procmail. NOTE: the vendor has stated this bug does not violate any security guarantees QEMU makes.    6.9  Medium  2017-05-27  2017-05-10  View
85321  CVE-2016-4892  Cross-site scripting vulnerability in SetsucoCMS all versions allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.    4.3  Medium  2017-05-27  2017-05-22  View
85577  CVE-2017-8454  Foxit Reader before 8.2.1 and PhantomPDF before 8.2.1 have an out-of-bounds read that allows remote attackers to obtain sensitive information or possibly execute arbitrary code via a crafted font in a PDF document.    6.8  Medium  2017-05-27  2017-05-12  View
86089  CVE-2017-8843  The join_pthread function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted archive.    4.3  Medium  2017-05-27  2017-05-16  View
85322  CVE-2016-4893  SQL injection vulnerability in the SetsucoCMS all versions allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.    6.5  Medium  2017-05-27  2017-05-22  View

Page 1617 of 17672, showing 5 records out of 88360 total, starting on record 8081, ending on 8085

Actions