NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
86670 | CVE-2017-9332 | The smarty_self function in modules/module_smarty.php in PivotX 2.3.11 mishandles the URI, allowing XSS via vectors involving quotes in the self Smarty tag. | 2 | 4.3 | Medium | 2017-06-17 | 2017-06-14 | View | |
86669 | CVE-2017-9330 | QEMU (aka Quick Emulator), when built with the USB OHCI Emulation support, allows local guest OS users to cause a denial of service (infinite loop) by leveraging an incorrect return value. | 2 | 1.9 | Low | 2017-07-18 | 2017-06-30 | View | |
86668 | CVE-2017-9324 | In Open Ticket Request System (OTRS) 3.3.x through 3.3.16, 4.x through 4.0.23, and 5.x through 5.0.19, an attacker with agent permission is capable of opening a specific URL in a browser to gain administrative privileges / full access. Afterward, all system settings can be read and changed. The URLs in question contain index.pl?Action=Installer with ;Subaction=Intro or ;Subaction=Start or ;Subaction=System appended at the end. | 2 | 6.5 | Medium | 2017-06-23 | 2017-06-22 | View | |
86667 | CVE-2017-9310 | QEMU (aka Quick Emulator), when built with the e1000e NIC emulation support, allows local guest OS privileged users to cause a denial of service (infinite loop) via vectors related to setting the initial receive / transmit descriptor head (TDH/RDH) outside the allocated descriptor buffer. | 2 | 1.9 | Low | 2017-07-18 | 2017-06-30 | View | |
86666 | CVE-2017-9128 | The quicktime_video_width function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted mp4 file. | 2 | 4.3 | Medium | 2017-06-17 | 2017-06-15 | View |
Page 339 of 17672, showing 5 records out of 88360 total, starting on record 1691, ending on 1695