NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 17450 | CVE-2016-10105 | admin/plugin.php in Piwigo through 2.8.3 doesn"t validate the sections variable while using it to include files. This can cause information disclosure and code execution if it contains a .. sequence. | 2 | 7.5 | High | 2017-01-19 | 2017-01-04 | View | |
| 82986 | CVE-2017-0078 | The kernel-mode drivers in Microsoft Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allow local users to gain privileges via a crafted application, aka Win32k Elevation of Privilege Vulnerability. This vulnerability is different from those described in CVE-2017-0024, CVE-2017-0026, CVE-2017-0056, CVE-2017-0079, CVE-2017-0080, CVE-2017-0081, CVE-2017-0082. | 2 | 7.2 | High | 2017-07-18 | 2017-07-11 | View | |
| 17706 | CVE-2016-1291 | Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allow remote attackers to execute arbitrary code via crafted deserialized data in an HTTP POST request, aka Bug ID CSCuw03192. | 2 | 9.3 | High | 2017-01-19 | 2016-12-02 | View | |
| 83242 | CVE-2017-5831 | Session fixation vulnerability in the forgot password mechanism in Revive Adserver before 4.0.1, when setting a new password, allows remote attackers to hijack web sessions via the session ID. | 2 | 5.5 | Medium | 2017-03-18 | 2017-03-06 | View | |
| 17962 | CVE-2016-1612 | The LoadIC::UpdateCaches function in ic/ic.cc in Google V8, as used in Google Chrome before 48.0.2564.82, does not ensure receiver compatibility before performing a cast of an unspecified variable, which allows remote attackers to cause a denial of service or possibly have unknown other impact via crafted JavaScript code. | 2 | 6.8 | Medium | 2017-01-19 | 2016-12-07 | View |
Page 2878 of 17672, showing 5 records out of 88360 total, starting on record 14386, ending on 14390