NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 18181 | CVE-2016-1833 | The htmlCurrentChar function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document. | 2 | 6.8 | Medium | 2017-01-19 | 2016-12-27 | View | |
| 18437 | CVE-2016-2163 | Cross-site scripting (XSS) vulnerability in Apache OpenMeetings before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the event description when creating an event. | 2 | 4.3 | Medium | 2017-01-19 | 2016-04-14 | View | |
| 18693 | CVE-2016-2480 | The mm-video-v4l2 vidc component in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 does not validate certain OMX parameter data structures, which allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 27532721. | 2 | 9.3 | High | 2017-01-19 | 2016-06-13 | View | |
| 18949 | CVE-2016-3068 | Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted git ext:: URL when cloning a subrepository. | 2 | 6.8 | Medium | 2017-01-19 | 2016-11-28 | View | |
| 19205 | CVE-2016-3390 | The scripting engines in Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, as demonstrated by the Chakra JavaScript engine, aka "Scripting Engine Memory Corruption Vulnerability." | 2 | 7.6 | High | 2017-01-19 | 2016-11-28 | View |
Page 2528 of 17672, showing 5 records out of 88360 total, starting on record 12636, ending on 12640