NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
17402 | CVE-2016-1000153 | Reflected XSS in wordpress plugin tidio-gallery v1.1 | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-22 | View | |
17658 | CVE-2016-1228 | Cross-site request forgery (CSRF) vulnerability on NTT EAST Hikari Denwa routers with firmware PR-400MI, RT-400MI, and RV-440MI 07.00.1006 and earlier and NTT WEST Hikari Denwa routers with firmware PR-400MI, RT-400MI, and RV-440MI 07.00.1005 and earlier allows remote attackers to hijack the authentication of arbitrary users. | 2 | 6.8 | Medium | 2017-01-19 | 2016-07-08 | View | |
83194 | CVE-2017-5232 | All editions of Rapid7 Nexpose installers prior to version 6.4.24 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL located in the current working directory of the installer. | 2 | 6.8 | Medium | 2017-03-29 | 2017-03-20 | View | |
17914 | CVE-2016-1521 | The directrun function in directmachine.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, does not validate a certain skip operation, which allows remote attackers to execute arbitrary code, obtain sensitive information, or cause a denial of service (out-of-bounds read and application crash) via a crafted Graphite smart font. | 2 | 6.8 | Medium | 2017-01-19 | 2016-12-05 | View | |
83450 | CVE-2017-6807 | mod_auth_mellon before 0.13.1 is vulnerable to a Cross-Site Session Transfer attack, where a user with access to one web site running on a server can copy their session cookie to a different web site on the same server to get access to that site. | 2 | 4.3 | Medium | 2017-03-18 | 2017-03-14 | View |
Page 17476 of 17672, showing 5 records out of 88360 total, starting on record 87376, ending on 87380