NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
22446  CVE-2016-9757  In the Create Tags page of the Rapid7 Nexpose version 6.4.12 user interface, any authenticated user who has the capability to create tags can inject cross-site scripting (XSS) elements in the tag name field. Once this tag is viewed in the Tag Detail page of the Rapid7 Nexpose 6.4.12 UI by another authenticated user, the script is run in that user"s browser context.    3.5  Low  2017-01-19  2016-12-27  View
26038  CVE-2015-4695  meta.h in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WMF file.    Medium  2017-01-19  2016-12-27  View
26039  CVE-2015-4696  Use-after-free vulnerability in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) via a crafted WMF file to the (1) wmf2gd or (2) wmf2eps command.    4.3  Medium  2017-01-19  2016-12-27  View
35770  CVE-2014-8891  Unspecified vulnerability in the Java Virtual Machine (JVM) in IBM SDK, Java Technology Edition 5.0 before SR16-FP9, 6 before SR16-FP3, 6R1 before SR8-FP3, 7 before SR8-FP10, and 7R1 before SR2-FP10 allows remote attackers to escape the Java sandbox and execute arbitrary code via unspecified vectors related to the security manager.    10  High  2017-01-19  2016-12-27  View
18110  CVE-2016-1762  The xmlNextChar function in libxml2 before 2.9.4 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document.    10  High  2017-01-19  2016-12-27  View

Page 3034 of 17672, showing 5 records out of 88360 total, starting on record 15166, ending on 15170

Actions