NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
85345 | CVE-2016-7051 | XmlMapper in the Jackson XML dataformat component (aka jackson-dataformat-xml) before 2.7.8 and 2.8.x before 2.8.4 allows remote attackers to conduct server-side request forgery (SSRF) attacks via vectors related to a DTD. | 2 | 5 | Medium | 2017-05-27 | 2017-05-25 | View | |
85601 | CVE-2017-8794 | An issue was discovered on Accellion FTA devices before FTA_9_12_180. Because a regular expression (intended to match local https URLs) lacks an initial ^ character, courier/web/1000@/wmProgressval.html allows SSRF attacks with a file:///etc/passwd#https:// URL pattern. | 2 | 6.4 | Medium | 2017-05-27 | 2017-05-17 | View | |
85857 | CVE-2017-2527 | An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the CoreAnimation component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory consumption and application crash) via crafted data. | 2 | 7.5 | High | 2017-07-18 | 2017-07-07 | View | |
86113 | CVE-2017-8879 | Dolibarr ERP/CRM 4.0.4 allows password changes without supplying the current password, which makes it easier for physically proximate attackers to obtain access via an unattended workstation. | 2 | 4.6 | Medium | 2017-05-27 | 2017-05-15 | View | |
86369 | CVE-2016-5177 | Use-after-free vulnerability in V8 in Google Chrome before 53.0.2785.143 allows remote attackers to cause a denial of service (crash) or possibly have unspecified other impact via unknown vectors. | 2 | 6.8 | Medium | 2017-06-12 | 2017-06-08 | View |
Page 16248 of 17672, showing 5 records out of 88360 total, starting on record 81236, ending on 81240