NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
84298  CVE-2017-2421  An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the AppleGraphicsPowerManagement component. A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app.    9.3  High  2017-07-18  2017-07-11  View
84554  CVE-2017-3543  Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Server). Supported versions that are affected are 11.1.1.8.0, 12.2.1.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Sites accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Sites. CVSS 3.0 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L).    High  2017-07-18  2017-07-10  View
85066  CVE-2017-8287  FreeType 2 before 2017-03-26 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_builder_close_contour function in psaux/psobjs.c.    7.5  High  2017-07-18  2017-06-30  View
85834  CVE-2017-2503  An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the Intel Graphics Driver component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.    9.3  High  2017-07-18  2017-07-07  View
87370  CVE-2017-2842  In the web management interface in Foscam C1 Indoor HD Camera running application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary data in the msmtprc configuration file resulting in command execution. An attacker can simply send an HTTP request to the device to trigger this vulnerability.    6.5  Medium  2017-07-18  2017-07-05  View

Page 16706 of 17672, showing 5 records out of 88360 total, starting on record 83526, ending on 83530

Actions