NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
83486  CVE-2017-6905  An issue was discovered in concrete5 <= 5.6.3.4. The vulnerability exists due to insufficient filtration of user-supplied data (disable_choose) passed to the concrete5-legacy-master/web/concrete/tools/files/search_dialog.php URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.    4.3  Medium  2017-03-29  2017-03-23  View
18206  CVE-2016-1859  The WebKit Canvas implementation in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.    6.8  Medium  2017-01-19  2016-11-30  View
83742  CVE-2017-5644  Apache POI in versions prior to release 3.15 allows remote attackers to cause a denial of service (CPU consumption) via a specially crafted OOXML file, aka an XML Entity Expansion (XEE) attack.    7.1  High  2017-03-29  2017-03-28  View
18462  CVE-2016-2193  PostgreSQL before 9.5.x before 9.5.2 does not properly maintain row-security status in cached plans, which might allow attackers to bypass intended access restrictions by leveraging a session that performs queries as more than one role.    Medium  2017-01-19  2016-04-14  View
83998  CVE-2016-9168  A missing X-Frame-Options header in the NDS Utility Monitor in NDSD in Novell eDirectory before 9.0.2 could be used by remote attackers for clickjacking.    4.3  Medium  2017-03-29  2017-03-27  View

Page 2064 of 17672, showing 5 records out of 88360 total, starting on record 10316, ending on 10320

Actions