NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
18449  CVE-2016-2179  The DTLS implementation in OpenSSL before 1.1.0 does not properly restrict the lifetime of queue entries associated with unused out-of-order messages, which allows remote attackers to cause a denial of service (memory consumption) by maintaining many crafted DTLS sessions simultaneously, related to d1_lib.c, statem_dtls.c, statem_lib.c, and statem_srvr.c.    Medium  2017-02-28  2017-02-23  View
83985  CVE-2016-8960  IBM Cognos Business Intelligence 10.2 could allow a user with lower privilege Capabilities to adopt the Capabilities of a higher-privilege user by intercepting the higher-privilege user"s cookie value from its HTTP request and then reusing it in subsequent requests. IBM Reference #: 1993718.    6.5  Medium  2017-03-29  2017-03-29  View
18705  CVE-2016-2492  The MediaTek power-management driver in Android before 2016-06-01 on Android One devices allows attackers to gain privileges via a crafted application, aka internal bug 28085410.    9.3  High  2017-01-19  2016-06-16  View
18961  CVE-2016-3085  Apache CloudStack 4.5.x before 4.5.2.1, 4.6.x before 4.6.2.1, 4.7.x before 4.7.1.1, and 4.8.x before 4.8.0.1, when SAML-based authentication is enabled and used, allow remote attackers to bypass authentication and access the user interface via vectors related to the SAML plugin.    5.8  Medium  2017-01-19  2016-06-14  View
19217  CVE-2016-3409  Cross-site scripting (XSS) vulnerability in Zimbra Collaboration before 8.7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka bug 102637.    4.3  Medium  2017-02-06  2017-02-01  View

Page 3246 of 17672, showing 5 records out of 88360 total, starting on record 16226, ending on 16230

Actions