NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
83340 | CVE-2017-6414 | Memory leak in the vcard_apdu_new function in card_7816.c in libcacard before 2.5.3 allows local guest OS users to cause a denial of service (host memory consumption) via vectors related to allocating a new APDU object. | 2 | 4.9 | Medium | 2017-03-29 | 2017-03-21 | View | |
83339 | CVE-2017-6413 | The OpenID Connect Relying Party and OAuth 2.0 Resource Server (aka mod_auth_openidc) module before 2.1.6 for the Apache HTTP Server does not skip OIDC_CLAIM_ and OIDCAuthNHeader headers in an AuthType oauth20 configuration, which allows remote attackers to bypass authentication via crafted HTTP traffic. | 2 | 5 | Medium | 2017-03-18 | 2017-03-06 | View | |
84736 | CVE-2017-6412 | In Sophos Web Appliance (SWA) before 4.3.1.2, Session Fixation could occur, aka NSWA-1310. | 2 | 6.8 | Medium | 2017-04-27 | 2017-04-14 | View | |
83338 | CVE-2017-6411 | Cross Site Request Forgery (CSRF) on D-Link DSL-2730U C1 IN_1.00 devices allows remote attackers to change the DNS or firewall configuration or any password. | 2 | 6.8 | Medium | 2017-03-18 | 2017-03-07 | View | |
83337 | CVE-2017-6410 | kpac/script.cpp in KDE kio before 5.32 and kdelibs before 4.14.30 calls the PAC FindProxyForURL function with a full https URL (potentially including Basic Authentication credentials, a query string, or PATH_INFO), which allows remote attackers to obtain sensitive information via a crafted PAC file. | 2 | 4.3 | Medium | 2017-03-18 | 2017-03-06 | View |
Page 381 of 17672, showing 5 records out of 88360 total, starting on record 1901, ending on 1905