NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
86665 | CVE-2017-9127 | The quicktime_user_atoms_read_atom function in useratoms.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) via a crafted mp4 file. | 2 | 4.3 | Medium | 2017-06-17 | 2017-06-15 | View | |
86921 | CVE-2017-1278 | IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0 and 6.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 124756. | 2 | 3.5 | Low | 2017-06-17 | 2017-06-16 | View | |
86666 | CVE-2017-9128 | The quicktime_video_width function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted mp4 file. | 2 | 4.3 | Medium | 2017-06-17 | 2017-06-15 | View | |
86670 | CVE-2017-9332 | The smarty_self function in modules/module_smarty.php in PivotX 2.3.11 mishandles the URI, allowing XSS via vectors involving quotes in the self Smarty tag. | 2 | 4.3 | Medium | 2017-06-17 | 2017-06-14 | View | |
86671 | CVE-2017-9355 | XML external entity (XXE) vulnerability in the import playlist feature in Subsonic 6.1.1 might allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted XSPF playlist file. | 2 | 4.3 | Medium | 2017-06-17 | 2017-06-16 | View |
Page 16188 of 17672, showing 5 records out of 88360 total, starting on record 80936, ending on 80940