NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
84765 | CVE-2017-6973 | A cross-site scripting (XSS) vulnerability in the MantisBT Configuration Report page (adm_config_report.php) allows remote attackers to inject arbitrary code through a crafted 'action' parameter. This is fixed in 1.3.8, 2.1.2, and 2.2.2. | 2 | 3.5 | Low | 2017-07-18 | 2017-07-11 | View | |
88349 | CVE-2016-10244 | The parse_charstrings function in type1/t1load.c in FreeType 2 before 2.7 does not ensure that a font contains a glyph name, which allows remote attackers to cause a denial of service (heap-based buffer over-read) or possibly have unspecified other impact via a crafted file. | 2 | 6.8 | Medium | 2017-07-18 | 2017-07-11 | View | |
82974 | CVE-2017-0065 | Microsoft Edge allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka Microsoft Browser Information Disclosure Vulnerability. This vulnerability is different from those described in CVE-2017-0009, CVE-2017-0011, CVE-2017-0017, and CVE-2017-0068. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-11 | View | |
84254 | CVE-2017-2376 | An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves the Safari component. It allows remote attackers to spoof the address bar by leveraging text input during the loading of a page. | 2 | 5 | Medium | 2017-07-18 | 2017-07-11 | View | |
84766 | CVE-2017-6974 | An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the system-installation subsystem of the System Integrity Protection component. It allows attackers to modify the contents of a protected disk location via a crafted app. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-11 | View |
Page 17434 of 17672, showing 5 records out of 88360 total, starting on record 87166, ending on 87170