NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
17714 | CVE-2016-1300 | Cross-site scripting (XSS) vulnerability in Cisco Unity Connection (UC) 10.5(2.3009) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCux82582. | 2 | 4.3 | Medium | 2017-01-19 | 2016-01-28 | View | |
83250 | CVE-2017-5852 | The PoDoFo::PdfPage::GetInheritedKeyFromObject function in base/PdfVariant.cpp in PoDoFo 0.9.4 allows remote attackers to cause a denial of service (infinite loop) via a crafted file. | 2 | 4.3 | Medium | 2017-03-29 | 2017-03-24 | View | |
83506 | CVE-2017-6966 | readelf in GNU Binutils 2.28 has a use-after-free (specifically read-after-free) error while processing multiple, relocated sections in an MSP430 binary. This is caused by mishandling of an invalid symbol index, and mishandling of state across invocations. | 2 | 4.3 | Medium | 2017-03-29 | 2017-03-20 | View | |
18226 | CVE-2016-1902 | The nextBytes function in the SecureRandom class in Symfony before 2.3.37, 2.6.x before 2.6.13, and 2.7.x before 2.7.9 does not properly generate random numbers when used with PHP 5.x without the paragonie/random_compat library and the openssl_random_pseudo_bytes function fails, which makes it easier for attackers to defeat cryptographic protection mechanisms via unspecified vectors. | 2 | 5 | Medium | 2017-01-19 | 2016-06-03 | View | |
83762 | CVE-2017-6068 | Subrion CMS 4.0.5 has CSRF in admin/blocks/add/. The attacker can create any block, and can optionally insert XSS via the content parameter. | 2 | 6.8 | Medium | 2017-03-29 | 2017-03-28 | View |
Page 1810 of 17672, showing 5 records out of 88360 total, starting on record 9046, ending on 9050