NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
22252  CVE-2016-9018  Improper handling of a repeating VRAT chunk in qcpfformat.dll allows attackers to cause a Null pointer dereference and crash in RealNetworks RealPlayer 18.1.5.705 through a crafted .QCP media file.    4.3  Medium  2017-01-19  2016-11-29  View
88300  CVE-2016-0238  IBM Security Guardium 9.0, 9.1, 9.5, 10.0, and 10.1 transmits sensitive data in cleartext in the query of the request. This could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 110409    4.3  Medium  2017-07-18  2017-07-11  View
23020  CVE-2015-0547  The D2CenterstageService.getComments service method in EMC Documentum D2 4.1 and 4.2 before 4.2 P16 and 4.5 before P03 allows remote authenticated users to conduct Documentum Query Language (DQL) injection attacks and bypass intended read-access restrictions via unspecified vectors.    Medium  2017-01-19  2016-12-27  View
25068  CVE-2015-3152  Oracle MySQL before 5.7.3, Oracle MySQL Connector/C (aka libmysqlclient) before 6.1.3, and MariaDB before 5.5.44 use the --ssl option to mean that SSL is optional, which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack, aka a "BACKRONYM" attack.    4.3  Medium  2017-01-19  2016-11-29  View
25324  CVE-2015-3677  The LZVN compression feature in AppleFSCompression in Apple OS X before 10.10.4 allows attackers to obtain sensitive memory-layout information for the kernel via a crafted app.    4.3  Medium  2017-01-19  2016-11-28  View

Page 16966 of 17672, showing 5 records out of 88360 total, starting on record 84826, ending on 84830

Actions