NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
86042 | CVE-2017-7661 | Apache CXF Fediz ships with a number of container-specific plugins to enable WS-Federation for applications. A CSRF (Cross Style Request Forgery) style vulnerability has been found in the Spring 2, Spring 3, Jetty 8 and Jetty 9 plugins in Apache CXF Fediz prior to 1.4.0, 1.3.2 and 1.2.4. | 2 | 6.8 | Medium | 2017-07-18 | 2017-07-07 | View | |
86298 | CVE-2017-9209 | libqpdf.a in QPDF 6.0.0 allows remote attackers to cause a denial of service (infinite recursion and stack consumption) via a crafted PDF document, related to QPDFObjectHandle::parseInternal, aka qpdf-infiniteloop2. | 2 | 4.3 | Medium | 2017-06-03 | 2017-06-01 | View | |
86554 | CVE-2016-10376 | Gajim through 0.16.7 unconditionally implements the XEP-0146: Remote Controlling Clients extension. This can be abused by malicious XMPP servers to, for example, extract plaintext from OTR encrypted sessions. | 2 | 3.5 | Low | 2017-07-18 | 2017-07-10 | View | |
86810 | CVE-2016-4908 | Cybozu Garoon 3.0.0 to 4.2.2 allows remote authenticated attackers to bypass access restriction to alter or delete another user's private RSS settings via unspecified vectors. | 2 | 4 | Medium | 2017-06-18 | 2017-06-13 | View | |
87066 | CVE-2017-8529 | Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, and Windows Server 2012 and R2 allow an attacker to detect specific files on the user's computer when affected Microsoft scripting engines do not properly handle objects in memory, aka Microsoft Browser Information Disclosure Vulnerability. | 2 | 4.3 | Medium | 2017-06-28 | 2017-06-26 | View |
Page 448 of 17672, showing 5 records out of 88360 total, starting on record 2236, ending on 2240