NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
21995 | CVE-2016-7998 | The SPIP template composer/compiler in SPIP 3.1.2 and earlier allows remote authenticated users to execute arbitrary PHP code by uploading an HTML file with a crafted (1) INCLUDE or (2) INCLURE tag and then accessing it with a valider_xml action. | 2 | 6.5 | Medium | 2017-05-27 | 2017-05-23 | View | |
22251 | CVE-2016-9017 | Artifex Software, Inc. MuJS before a5c747f1d40e8d6659a37a8d25f13fb5acf8e767 allows context-dependent attackers to obtain sensitive information by using the "opname in crafted JavaScript file" approach, related to an "Out-of-Bounds read" issue affecting the jsC_dumpfunction function in the jsdump.c component. | 2 | 5 | Medium | 2017-01-19 | 2016-11-29 | View | |
87787 | CVE-2017-11126 | The III_i_stereo function in libmpg123/layer3.c in mpg123 through 1.25.1 allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted audio file that is mishandled in the code for the block_type != 2 case, a similar issue to CVE-2017-9870. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-13 | View | |
22763 | CVE-2015-0282 | GnuTLS before 3.1.0 does not verify that the RSA PKCS #1 signature algorithm matches the signature algorithm in the certificate, which allows remote attackers to conduct downgrade attacks via unspecified vectors. | 2 | 5 | Medium | 2017-01-19 | 2016-11-28 | View | |
24043 | CVE-2015-1806 | The combination filter Groovy script in Jenkins before 1.600 and LTS before 1.596.1 allows remote authenticated users with job configuration permission to gain privileges and execute arbitrary code on the master via unspecified vectors. | 2 | 6.5 | Medium | 2017-01-19 | 2016-06-15 | View |
Page 16934 of 17672, showing 5 records out of 88360 total, starting on record 84666, ending on 84670