NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
18447  CVE-2016-2177  OpenSSL through 1.0.2h incorrectly uses pointer arithmetic for heap-buffer boundary checks, which might allow remote attackers to cause a denial of service (integer overflow and application crash) or possibly have unspecified other impact by leveraging unexpected malloc behavior, related to s3_srvr.c, ssl_sess.c, and t1_lib.c.    7.5  High  2017-02-28  2017-02-23  View
18446  CVE-2016-2176  The X509_NAME_oneline function in crypto/x509/x509_obj.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to obtain sensitive information from process stack memory or cause a denial of service (buffer over-read) via crafted EBCDIC ASN.1 data.    6.4  Medium  2017-06-12  2017-06-08  View
18445  CVE-2016-2175  Apache PDFBox before 1.8.12 and 2.x before 2.0.1 does not properly initialize the XML parsers, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted PDF.    7.5  High  2017-01-19  2017-01-06  View
18444  CVE-2016-2174  SQL injection vulnerability in the policy admin tool in Apache Ranger before 0.5.3 allows remote authenticated administrators to execute arbitrary SQL commands via the eventTime parameter to service/plugins/policies/eventTime.    6.5  Medium  2017-01-19  2016-06-14  View
85129  CVE-2016-2173  org.springframework.core.serializer.DefaultDeserializer in Spring AMQP before 1.5.5 allows remote attackers to execute arbitrary code.          2017-04-27  2017-04-21  View

Page 2077 of 17672, showing 5 records out of 88360 total, starting on record 10381, ending on 10385

Actions