NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
84095  CVE-2016-6816  The code in Apache Tomcat 9.0.0.M1 to 9.0.0.M11, 8.5.0 to 8.5.6, 8.0.0.RC1 to 8.0.38, 7.0.0 to 7.0.72, and 6.0.0 to 6.0.47 that parsed the HTTP request line permitted invalid characters. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpretation, to inject data into the HTTP response. By manipulating the HTTP response the attacker could poison a web-cache, perform an XSS attack and/or obtain sensitive information from requests other then their own.    6.8  Medium  2017-03-29  2017-03-24  View
83852  CVE-2017-7259  ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.        2017-03-29  2017-03-24  View
82589  CVE-2017-5928  The W3C High Resolution Time API, as implemented in various web browsers, does not consider that memory-reference times can be measured by a performance.now Time to Tick approach even with the https://bugzilla.mozilla.org/show_bug.cgi?id=1167489#c9 protection mechanism in place, which makes it easier for remote attackers to conduct AnC attacks via crafted JavaScript code.    4.3  Medium  2017-03-29  2017-03-24  View
83875  CVE-2014-9832  Heap overflow in ImageMagick 6.8.9-9 via a crafted pcx file.    6.8  Medium  2017-03-29  2017-03-24  View
83876  CVE-2014-9833  Heap overflow in ImageMagick 6.8.9-9 via a crafted psd file.    6.8  Medium  2017-03-29  2017-03-24  View

Page 1922 of 17672, showing 5 records out of 88360 total, starting on record 9606, ending on 9610

Actions