NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 18617 | CVE-2016-2392 | The is_rndis function in the USB Net device emulator (hw/usb/dev-network.c) in QEMU before 2.5.1 does not properly validate USB configuration descriptor objects, which allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) via vectors involving a remote NDIS control message packet. | 2 | 2.1 | Low | 2017-01-19 | 2016-11-28 | View | |
| 18616 | CVE-2016-2391 | The ohci_bus_start function in the USB OHCI emulation support (hw/usb/hcd-ohci.c) in QEMU allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) via vectors related to multiple eof_timers. | 2 | 2.1 | Low | 2017-01-19 | 2016-11-28 | View | |
| 18615 | CVE-2016-2390 | The FwdState::connectedToPeer method in FwdState.cc in Squid before 3.5.14 and 4.0.x before 4.0.6 does not properly handle SSL handshake errors when built with the --with-openssl option, which allows remote attackers to cause a denial of service (application crash) via a plaintext HTTP message. | 2 | 4.3 | Medium | 2017-01-19 | 2016-11-28 | View | |
| 18614 | CVE-2016-2389 | Directory traversal vulnerability in the GetFileList function in the SAP Manufacturing Integration and Intelligence (xMII) component 15.0 for SAP NetWeaver 7.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the Path parameter to /Catalog, aka SAP Security Note 2230978. | 2 | 7.8 | High | 2017-01-19 | 2016-11-30 | View | |
| 18613 | CVE-2016-2388 | The Universal Worklist Configuration in SAP NetWeaver 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP request, aka SAP Security Note 2256846. | 2 | 5 | Medium | 2017-01-19 | 2016-11-30 | View |
Page 2041 of 17672, showing 5 records out of 88360 total, starting on record 10201, ending on 10205