NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
22252 | CVE-2016-9018 | Improper handling of a repeating VRAT chunk in qcpfformat.dll allows attackers to cause a Null pointer dereference and crash in RealNetworks RealPlayer 18.1.5.705 through a crafted .QCP media file. | 2 | 4.3 | Medium | 2017-01-19 | 2016-11-29 | View | |
88300 | CVE-2016-0238 | IBM Security Guardium 9.0, 9.1, 9.5, 10.0, and 10.1 transmits sensitive data in cleartext in the query of the request. This could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 110409 | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-11 | View | |
23020 | CVE-2015-0547 | The D2CenterstageService.getComments service method in EMC Documentum D2 4.1 and 4.2 before 4.2 P16 and 4.5 before P03 allows remote authenticated users to conduct Documentum Query Language (DQL) injection attacks and bypass intended read-access restrictions via unspecified vectors. | 2 | 4 | Medium | 2017-01-19 | 2016-12-27 | View | |
25068 | CVE-2015-3152 | Oracle MySQL before 5.7.3, Oracle MySQL Connector/C (aka libmysqlclient) before 6.1.3, and MariaDB before 5.5.44 use the --ssl option to mean that SSL is optional, which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack, aka a "BACKRONYM" attack. | 2 | 4.3 | Medium | 2017-01-19 | 2016-11-29 | View | |
25324 | CVE-2015-3677 | The LZVN compression feature in AppleFSCompression in Apple OS X before 10.10.4 allows attackers to obtain sensitive memory-layout information for the kernel via a crafted app. | 2 | 4.3 | Medium | 2017-01-19 | 2016-11-28 | View |
Page 16966 of 17672, showing 5 records out of 88360 total, starting on record 84826, ending on 84830