NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 18449 | CVE-2016-2179 | The DTLS implementation in OpenSSL before 1.1.0 does not properly restrict the lifetime of queue entries associated with unused out-of-order messages, which allows remote attackers to cause a denial of service (memory consumption) by maintaining many crafted DTLS sessions simultaneously, related to d1_lib.c, statem_dtls.c, statem_lib.c, and statem_srvr.c. | 2 | 5 | Medium | 2017-02-28 | 2017-02-23 | View | |
| 83985 | CVE-2016-8960 | IBM Cognos Business Intelligence 10.2 could allow a user with lower privilege Capabilities to adopt the Capabilities of a higher-privilege user by intercepting the higher-privilege user"s cookie value from its HTTP request and then reusing it in subsequent requests. IBM Reference #: 1993718. | 2 | 6.5 | Medium | 2017-03-29 | 2017-03-29 | View | |
| 18705 | CVE-2016-2492 | The MediaTek power-management driver in Android before 2016-06-01 on Android One devices allows attackers to gain privileges via a crafted application, aka internal bug 28085410. | 2 | 9.3 | High | 2017-01-19 | 2016-06-16 | View | |
| 18961 | CVE-2016-3085 | Apache CloudStack 4.5.x before 4.5.2.1, 4.6.x before 4.6.2.1, 4.7.x before 4.7.1.1, and 4.8.x before 4.8.0.1, when SAML-based authentication is enabled and used, allow remote attackers to bypass authentication and access the user interface via vectors related to the SAML plugin. | 2 | 5.8 | Medium | 2017-01-19 | 2016-06-14 | View | |
| 19217 | CVE-2016-3409 | Cross-site scripting (XSS) vulnerability in Zimbra Collaboration before 8.7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka bug 102637. | 2 | 4.3 | Medium | 2017-02-06 | 2017-02-01 | View |
Page 3246 of 17672, showing 5 records out of 88360 total, starting on record 16226, ending on 16230