NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
19765  CVE-2016-4060  Use-after-free vulnerability in Foxit Reader and PhantomPDF before 7.3.4 on Windows allows remote attackers to cause a denial of service (application crash) via unspecified vectors.    Medium  2017-01-19  2016-11-28  View
85301  CVE-2016-4068  Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG, a different vulnerability than CVE-2015-8864.    4.3  Medium  2017-04-27  2017-04-19  View
20021  CVE-2016-4343  The phar_make_dirstream function in ext/phar/dirstream.c in PHP before 5.6.18 and 7.x before 7.0.3 mishandles zero-size ././@LongLink files, which allows remote attackers to cause a denial of service (uninitialized pointer dereference) or possibly have unspecified other impact via a crafted TAR archive.    6.8  Medium  2017-01-19  2016-11-30  View
85557  CVE-2017-8383  Craft CMS before 2.6.2976 does not properly restrict viewing the contents of files in the craft/app/ folder.    Medium  2017-05-27  2017-05-11  View
20277  CVE-2016-4708  CFNetwork in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 misparses the Set-Cookie header, which allows remote attackers to obtain sensitive information via a crafted HTTP response.    4.3  Medium  2017-01-19  2016-11-28  View

Page 1919 of 17672, showing 5 records out of 88360 total, starting on record 9591, ending on 9595

Actions