NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
17714  CVE-2016-1300  Cross-site scripting (XSS) vulnerability in Cisco Unity Connection (UC) 10.5(2.3009) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCux82582.    4.3  Medium  2017-01-19  2016-01-28  View
83250  CVE-2017-5852  The PoDoFo::PdfPage::GetInheritedKeyFromObject function in base/PdfVariant.cpp in PoDoFo 0.9.4 allows remote attackers to cause a denial of service (infinite loop) via a crafted file.    4.3  Medium  2017-03-29  2017-03-24  View
83506  CVE-2017-6966  readelf in GNU Binutils 2.28 has a use-after-free (specifically read-after-free) error while processing multiple, relocated sections in an MSP430 binary. This is caused by mishandling of an invalid symbol index, and mishandling of state across invocations.    4.3  Medium  2017-03-29  2017-03-20  View
18226  CVE-2016-1902  The nextBytes function in the SecureRandom class in Symfony before 2.3.37, 2.6.x before 2.6.13, and 2.7.x before 2.7.9 does not properly generate random numbers when used with PHP 5.x without the paragonie/random_compat library and the openssl_random_pseudo_bytes function fails, which makes it easier for attackers to defeat cryptographic protection mechanisms via unspecified vectors.    Medium  2017-01-19  2016-06-03  View
83762  CVE-2017-6068  Subrion CMS 4.0.5 has CSRF in admin/blocks/add/. The attacker can create any block, and can optionally insert XSS via the content parameter.    6.8  Medium  2017-03-29  2017-03-28  View

Page 1810 of 17672, showing 5 records out of 88360 total, starting on record 9046, ending on 9050

Actions