NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
17950  CVE-2016-1595  LiveTime/WebObjects/LiveTime.woa/wa/DownloadAction/downloadFile in Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to conduct Hibernate Query Language (HQL) injection attacks and obtain sensitive information via the entityName parameter.    Medium  2017-01-19  2016-12-02  View
18206  CVE-2016-1859  The WebKit Canvas implementation in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.    6.8  Medium  2017-01-19  2016-11-30  View
18462  CVE-2016-2193  PostgreSQL before 9.5.x before 9.5.2 does not properly maintain row-security status in cached plans, which might allow attackers to bypass intended access restrictions by leveraging a session that performs queries as more than one role.    Medium  2017-01-19  2016-04-14  View
18718  CVE-2016-2505  mpeg2ts/ATSParser.cpp in libstagefright in mediaserver in Android 6.x before 2016-07-01 does not validate a certain section length, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 28333006.    9.3  High  2017-01-19  2016-07-12  View
18974  CVE-2016-3116  CRLF injection vulnerability in Dropbear SSH before 2016.72 allows remote authenticated users to bypass intended shell-command restrictions via crafted X11 forwarding data.    5.5  Medium  2017-01-19  2016-12-02  View

Page 2954 of 17672, showing 5 records out of 88360 total, starting on record 14766, ending on 14770

Actions