NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
20476 | CVE-2016-5137 | The CSPSource::schemeMatches function in WebKit/Source/core/frame/csp/CSPSource.cpp in the Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 52.0.2743.82, does not apply http :80 policies to https :443 URLs and does not apply ws :80 policies to wss :443 URLs, which makes it easier for remote attackers to determine whether a specific HSTS web site has been visited by reading a CSP report. NOTE: this vulnerability is associated with a specification change after CVE-2016-1617 resolution. | 2 | 4.3 | Medium | 2017-01-19 | 2016-11-28 | View | |
86012 | CVE-2017-7236 | SQL injection vulnerability in NetApp OnCommand Unified Manager Core Package 5.x before 5.2.2P1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | 2 | 5 | Medium | 2017-06-03 | 2017-06-02 | View | |
20732 | CVE-2016-5486 | Unspecified vulnerability in the Sun ZFS Storage Appliance Kit (AK) component in Oracle Sun Systems Products Suite AK 2013 allows local users to affect confidentiality via vectors related to Core Services. | 2 | 4.9 | Medium | 2017-01-19 | 2016-11-28 | View | |
86268 | CVE-2017-9179 | libautotrace.a in AutoTrace 0.31.1 allows remote attackers to cause a denial of service (invalid read and SEGV), related to the ReadImage function in input-bmp.c:425:14. | 2 | 5 | Medium | 2017-06-03 | 2017-05-28 | View | |
20988 | CVE-2016-5890 | IBM Sterling B2B Integrator 5.2 before 5020500_14 and 5.2 06 before 5020602_1 allows remote authenticated users to change arbitrary passwords via unspecified vectors. | 2 | 3.5 | Low | 2017-01-19 | 2016-12-02 | View |
Page 17083 of 17672, showing 5 records out of 88360 total, starting on record 85411, ending on 85415