NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
83254  CVE-2017-5856  Memory leak in the megasas_handle_dcmd function in hw/scsi/megasas.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption) via MegaRAID Firmware Interface (MFI) commands with the sglist size set to a value over 2 Gb.    4.9  Medium  2017-07-18  2017-06-30  View
17974  CVE-2016-1624  Integer underflow in the ProcessCommandsInternal function in dec/decode.c in Brotli, as used in Google Chrome before 48.0.2564.109, allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via crafted data with brotli compression.    6.8  Medium  2017-01-19  2016-12-05  View
18486  CVE-2016-2221  Open redirect vulnerability in the wp_validate_redirect function in wp-includes/pluggable.php in WordPress before 4.4.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a malformed URL that triggers incorrect hostname parsing, as demonstrated by an https:example.com URL.    5.8  Medium  2017-01-19  2016-11-28  View
84022  CVE-2016-9455  Revive Adserver before 3.2.3 suffers from Cross-Site Request Forgery (CSRF). A number of scripts in Revive Adserver"s user interface are vulnerable to CSRF attacks: `www/admin/banner-acl.php`, `www/admin/banner-activate.php`, `www/admin/banner-advanced.php`, `www/admin/banner-modify.php`, `www/admin/banner-swf.php`, `www/admin/banner-zone.php`, `www/admin/tracker-modify.php`.    6.8  Medium  2017-03-29  2017-03-29  View
18742  CVE-2016-2537  The is-my-json-valid package before 2.12.4 for Node.js has an incorrect exports["utc-millisec"] regular expression, which allows remote attackers to cause a denial of service (blocked event loop) via a crafted string.    Medium  2017-01-19  2016-02-29  View

Page 1954 of 17672, showing 5 records out of 88360 total, starting on record 9766, ending on 9770

Actions