NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
84809  CVE-2017-7361  Pixie 1.0.4 allows an admin/index.php s=publish&m=static&x= XSS attack.    4.3  Medium  2017-04-27  2017-04-04  View
85065  CVE-2017-8284  ** DISPUTED ** The disas_insn function in target/i386/translate.c in QEMU before 2.9.0, when TCG mode without hardware acceleration is used, does not limit the instruction size, which allows local users to gain privileges by creating a modified basic block that injects code into a setuid program, as demonstrated by procmail. NOTE: the vendor has stated this bug does not violate any security guarantees QEMU makes.    6.9  Medium  2017-05-27  2017-05-10  View
19785  CVE-2016-4083  epan/dissectors/packet-mswsp.c in the MS-WSP dissector in Wireshark 2.0.x before 2.0.3 does not ensure that data is available before array allocation, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.    4.3  Medium  2017-01-19  2016-12-02  View
85321  CVE-2016-4892  Cross-site scripting vulnerability in SetsucoCMS all versions allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.    4.3  Medium  2017-05-27  2017-05-22  View
85577  CVE-2017-8454  Foxit Reader before 8.2.1 and PhantomPDF before 8.2.1 have an out-of-bounds read that allows remote attackers to obtain sensitive information or possibly execute arbitrary code via a crafted font in a PDF document.    6.8  Medium  2017-05-27  2017-05-12  View

Page 2640 of 17672, showing 5 records out of 88360 total, starting on record 13196, ending on 13200

Actions