NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
86608 | CVE-2017-4901 | The drag-and-drop (DnD) function in VMware Workstation 12.x before version 12.5.4 and Fusion 8.x before version 8.5.5 has an out-of-bounds memory access vulnerability. This may allow a guest to execute code on the operating system that runs Workstation or Fusion. | 2 | 7.5 | High | 2017-07-18 | 2017-07-11 | View | |
87120 | CVE-2017-9579 | The JMCU Mobile Banking by Joplin Metro Credit Union app 3.0.0 -- aka jmcu-mobile-banking/id716065893 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | 2 | 4.3 | Medium | 2017-07-18 | 2017-06-28 | View | |
87632 | CVE-2017-10672 | Use-after-free in the XML-LibXML module through 2.0129 for Perl allows remote attackers to execute arbitrary code by controlling the arguments to a replaceChild call. | 2 | 7.5 | High | 2017-07-18 | 2017-07-05 | View | |
87888 | CVE-2017-1321 | IBM InfoSphere Information Server 9.1, 11.3, and 11.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125916. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-17 | View | |
88144 | CVE-2017-8560 | Microsoft Exchange Server 2010 SP3, Exchange Server 2013 SP3, Exchange Server 2013 CU16, and Exchange Server 2016 CU5 allows an elevation of privilege vulnerability due to the way that Exchange Outlook Web Access (OWA) handles web requests, aka Microsoft Exchange Cross-Site Scripting Vulnerability. This CVE ID is unique from CVE-2017-8559. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-14 | View |
Page 16739 of 17672, showing 5 records out of 88360 total, starting on record 83691, ending on 83695