NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
84878 | CVE-2017-7589 | In OpenIDM through 4.0.0 before 4.5.0, the info endpoint may leak sensitive information upon a request by the anonymous user, as demonstrated by responses with a 200 HTTP status code and a JSON object containing IP address strings. This is related to a missing access-control check in bin/defaults/script/info/login.js. | 2 | 4 | Medium | 2017-04-27 | 2017-04-13 | View | |
85134 | CVE-2016-3076 | Heap-based buffer overflow in the j2k_encode_entry function in Pillow 2.5.0 through 3.1.1 allows remote attackers to cause a denial of service (memory corruption) via a crafted Jpeg2000 file. | 2017-04-27 | 2017-04-24 | View | ||||
84367 | CVE-2017-2647 | The KEYS subsystem in the Linux kernel before 3.18 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via vectors involving a NULL value for a certain match field, related to the keyring_search_iterator function in keyring.c. | 2 | 7.2 | High | 2017-04-27 | 2017-04-04 | View | |
85135 | CVE-2016-3109 | The backend/Login/load/ script in Shopware before 5.1.5 allows remote attackers to execute arbitrary code. | 2017-04-27 | 2017-04-25 | View | ||||
84368 | CVE-2017-2671 | The ping_unhash function in net/ipv4/ping.c in the Linux kernel through 4.10.8 is too late in obtaining a certain lock and consequently cannot ensure that disconnect function calls are safe, which allows local users to cause a denial of service (panic) by leveraging access to the protocol value of IPPROTO_ICMP in a socket system call. | 2 | 4.9 | Medium | 2017-04-27 | 2017-04-11 | View |
Page 1818 of 17672, showing 5 records out of 88360 total, starting on record 9086, ending on 9090