NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
84892 | CVE-2017-7603 | au_channel.h in HE-AAC+ Codec (aka libaacplus) 2.0.2 has a signed integer overflow, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted audio file. | 2 | 6.8 | Medium | 2017-04-27 | 2017-04-13 | View | |
85404 | CVE-2017-2124 | Cross-site scripting vulnerability in OneThird CMS v1.73 Heaven's Door and earlier allows remote attackers to inject arbitrary web script or HTML via contact.php. | 2 | 4.3 | Medium | 2017-05-27 | 2017-05-24 | View | |
85660 | CVE-2016-7841 | Cross-site scripting vulnerability in Olive Diary DX allows remote attackers to inject arbitrary web script or HTML via the page parameter. | 2 | 4.3 | Medium | 2017-05-08 | 2017-05-05 | View | |
85916 | CVE-2017-4017 | User Name Disclosure in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote attackers to view user information via the appliance web interface. | 2 | 5 | Medium | 2017-07-18 | 2017-07-07 | View | |
86172 | CVE-2017-9045 | The Google I/O 2017 application before 5.1.4 for Android downloads multiple .json files from http://storage.googleapis.com without SSL, which makes it easier for man-in-the-middle attackers to spoof Feed and Schedule data by creating a modified blocks_v4.json file. | 2 | 4.3 | Medium | 2017-06-03 | 2017-05-31 | View |
Page 16681 of 17672, showing 5 records out of 88360 total, starting on record 83401, ending on 83405