NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
87783 | CVE-2017-11112 | In ncurses 6.0, there is an attempted 0xffffffffffffffff access in the append_acs function of tinfo/parse_entry.c. It could lead to a remote denial of service attack if the terminfo library code is used to process untrusted terminfo data. | 2 | 5 | Medium | 2017-07-18 | 2017-07-13 | View | |
22759 | CVE-2015-0275 | The ext4_zero_range function in fs/ext4/extents.c in the Linux kernel before 4.1 allows local users to cause a denial of service (BUG) via a crafted fallocate zero-range request. | 2 | 4.9 | Medium | 2017-01-19 | 2016-12-07 | View | |
88295 | CVE-2014-7953 | Race condition in the bindBackupAgent method in the ActivityManagerService in Android 4.4.4 allows local users with adb shell access to execute arbitrary code or any valid package as system by running pm install with the target apk, and simultaneously running a crafted script to process logcat's output looking for a dexopt line, which once found should execute bindBackupAgent with the uid member of the ApplicationInfo parameter set to 1000. | 2 | 6.9 | Medium | 2017-07-18 | 2017-07-13 | View | |
23015 | CVE-2015-0542 | Multiple cross-site request forgery (CSRF) vulnerabilities in EMC RSA Archer GRC 5.5 SP1 before P3 allow remote attackers to hijack the authentication of arbitrary users. | 2 | 6.8 | Medium | 2017-01-19 | 2016-11-28 | View | |
23271 | CVE-2015-0832 | Mozilla Firefox before 36.0 does not properly recognize the equivalence of domain names with and without a trailing . (dot) character, which allows man-in-the-middle attackers to bypass the HPKP and HSTS protection mechanisms by constructing a URL with this character and leveraging access to an X.509 certificate for a domain with this character. | 2 | 5 | Medium | 2017-01-19 | 2016-12-21 | View |
Page 16804 of 17672, showing 5 records out of 88360 total, starting on record 84016, ending on 84020