NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
83501 | CVE-2017-6958 | An XSS vulnerability in the MantisBT Source Integration Plugin (before 2.0.2) search result page allows an attacker to inject arbitrary HTML or JavaScript (if MantisBT's CSP settings permit it) by crafting any valid parameter. | 2 | 4.3 | Medium | 2017-03-29 | 2017-03-20 | View | |
18221 | CVE-2016-1897 | FFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using the concat protocol in an HTTP Live Streaming (HLS) M3U8 file, leading to an external HTTP request in which the URL string contains the first line of a local file. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-07 | View | |
84013 | CVE-2016-9392 | The calcstepsizes function in jpc_dec.c in JasPer before 1.900.17 allows remote attackers to cause a denial of service (assertion failure) via a crafted file. | 2 | 4.3 | Medium | 2017-03-29 | 2017-03-27 | View | |
18733 | CVE-2016-2526 | epan/dissectors/packet-hiqnet.c in the HiQnet dissector in Wireshark 2.0.x before 2.0.2 does not validate the data type, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted packet. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-02 | View | |
84269 | CVE-2017-2391 | An issue was discovered in certain Apple products. Pages before 6.1, Numbers before 4.1, and Keynote before 7.1 on macOS and Pages before 3.1, Numbers before 3.1, and Keynote before 3.1 on iOS are affected. The issue involves the Export component. It allows users to bypass iWork PDF password protection by leveraging use of 40-bit RC4. | 2 | 5 | Medium | 2017-07-18 | 2017-07-11 | View |
Page 1635 of 17672, showing 5 records out of 88360 total, starting on record 8171, ending on 8175