NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
86043 | CVE-2017-7662 | Apache CXF Fediz ships with an OpenId Connect (OIDC) service which has a Client Registration Service, which is a simple web application that allows clients to be created, deleted, etc. A CSRF (Cross Style Request Forgery) style vulnerability has been found in this web application in Apache CXF Fediz prior to 1.4.0 and 1.3.2, meaning that a malicious web application could create new clients, or reset secrets, etc, after the admin user has logged on to the client registration service and the session is still active. | 2 | 6.8 | Medium | 2017-07-18 | 2017-07-07 | View | |
87067 | CVE-2017-8530 | Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to trick a user into loading a page with malicious content when Microsoft Edge does not properly enforce same-origin policies, aka Microsoft Edge Security Feature Bypass Vulnerability. This CVE ID is unique from CVE-2017-8523 and CVE-2017-8555. | 2 | 5.8 | Medium | 2017-07-18 | 2017-07-07 | View | |
87579 | CVE-2017-1000042 | Mapbox.js versions 1.x prior to 1.6.5 and 2.x prior to 2.1.7 are vulnerable to a cross-site-scripting attack in certain uncommon usage scenarios via TileJSON Name. | 2017-07-18 | 2017-07-17 | View | ||||
87835 | CVE-2017-11338 | There is an infinite loop in the Exiv2::Image::printIFDStructure function of image.cpp in Exiv2 0.26. A crafted input will lead to a remote denial of service attack. | 2017-07-18 | 2017-07-17 | View | ||||
88091 | CVE-2017-7680 | Apache OpenMeetings 1.0.0 has an overly permissive crossdomain.xml file. This allows for flash content to be loaded from untrusted domains. | 2017-07-18 | 2017-07-17 | View |
Page 165 of 17672, showing 5 records out of 88360 total, starting on record 821, ending on 825