NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 84815 | CVE-2017-7379 | The PoDoFo::PdfSimpleEncoding::ConvertToEncoding function in PdfEncoding.cpp in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted PDF document. | 2 | 4.3 | Medium | 2017-04-27 | 2017-04-06 | View | |
| 20047 | CVE-2016-4370 | HPE Project and Portfolio Management Center (PPM) 9.2x and 9.3x before 9.32.0002 allows remote authenticated users to execute arbitrary commands or obtain sensitive information via unspecified vectors. | 2 | 6.5 | Medium | 2017-01-19 | 2016-06-10 | View | |
| 85583 | CVE-2017-8763 | Cross-site scripting (XSS) vulnerability in modules/Base/Box/check_for_new_version.php in EPESI in Telaxus/EPESI 1.8.2 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted URI that lacks the cid parameter. | 2 | 4.3 | Medium | 2017-05-27 | 2017-05-15 | View | |
| 85839 | CVE-2017-2508 | An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The issue involves the WebKit component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site that improperly interacts with container nodes. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-07 | View | |
| 20559 | CVE-2016-5226 | Blink in Google Chrome prior to 55.0.2883.75 for Linux, Windows and Mac executed javascript: URLs entered in the URL bar in the context of the current tab, which allowed a socially engineered user to XSS themselves by dragging and dropping a javascript: URL into the URL bar. | 2 | 4.3 | Medium | 2017-01-30 | 2017-01-23 | View |
Page 2842 of 17672, showing 5 records out of 88360 total, starting on record 14206, ending on 14210