NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
19765 | CVE-2016-4060 | Use-after-free vulnerability in Foxit Reader and PhantomPDF before 7.3.4 on Windows allows remote attackers to cause a denial of service (application crash) via unspecified vectors. | 2 | 5 | Medium | 2017-01-19 | 2016-11-28 | View | |
85301 | CVE-2016-4068 | Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG, a different vulnerability than CVE-2015-8864. | 2 | 4.3 | Medium | 2017-04-27 | 2017-04-19 | View | |
20021 | CVE-2016-4343 | The phar_make_dirstream function in ext/phar/dirstream.c in PHP before 5.6.18 and 7.x before 7.0.3 mishandles zero-size ././@LongLink files, which allows remote attackers to cause a denial of service (uninitialized pointer dereference) or possibly have unspecified other impact via a crafted TAR archive. | 2 | 6.8 | Medium | 2017-01-19 | 2016-11-30 | View | |
85557 | CVE-2017-8383 | Craft CMS before 2.6.2976 does not properly restrict viewing the contents of files in the craft/app/ folder. | 2 | 5 | Medium | 2017-05-27 | 2017-05-11 | View | |
20277 | CVE-2016-4708 | CFNetwork in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 misparses the Set-Cookie header, which allows remote attackers to obtain sensitive information via a crafted HTTP response. | 2 | 4.3 | Medium | 2017-01-19 | 2016-11-28 | View |
Page 1919 of 17672, showing 5 records out of 88360 total, starting on record 9591, ending on 9595