NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
20476 | CVE-2016-5137 | The CSPSource::schemeMatches function in WebKit/Source/core/frame/csp/CSPSource.cpp in the Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 52.0.2743.82, does not apply http :80 policies to https :443 URLs and does not apply ws :80 policies to wss :443 URLs, which makes it easier for remote attackers to determine whether a specific HSTS web site has been visited by reading a CSP report. NOTE: this vulnerability is associated with a specification change after CVE-2016-1617 resolution. | 2 | 4.3 | Medium | 2017-01-19 | 2016-11-28 | View | |
86012 | CVE-2017-7236 | SQL injection vulnerability in NetApp OnCommand Unified Manager Core Package 5.x before 5.2.2P1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | 2 | 5 | Medium | 2017-06-03 | 2017-06-02 | View | |
20732 | CVE-2016-5486 | Unspecified vulnerability in the Sun ZFS Storage Appliance Kit (AK) component in Oracle Sun Systems Products Suite AK 2013 allows local users to affect confidentiality via vectors related to Core Services. | 2 | 4.9 | Medium | 2017-01-19 | 2016-11-28 | View | |
86268 | CVE-2017-9179 | libautotrace.a in AutoTrace 0.31.1 allows remote attackers to cause a denial of service (invalid read and SEGV), related to the ReadImage function in input-bmp.c:425:14. | 2 | 5 | Medium | 2017-06-03 | 2017-05-28 | View | |
21244 | CVE-2016-6471 | A vulnerability in the web-based management interface of Cisco Firepower Management Center running FireSIGHT System software could allow an authenticated, remote attacker to view the Remote Storage Password. More Information: CSCvb19366. Known Affected Releases: 5.4.1.6. | 2 | 4 | Medium | 2017-01-19 | 2017-01-05 | View |
Page 17548 of 17672, showing 5 records out of 88360 total, starting on record 87736, ending on 87740