NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
86541 | CVE-2017-9403 | In LibTIFF 4.0.7, a memory leak vulnerability was found in the function TIFFReadDirEntryLong8Array in tif_dirread.c, which allows attackers to cause a denial of service via a crafted file. | 2 | 4.3 | Medium | 2017-06-12 | 2017-06-06 | View | |
21261 | CVE-2016-6504 | epan/dissectors/packet-ncp2222.inc in the NDS dissector in Wireshark 1.12.x before 1.12.13 does not properly maintain a ptvc data structure, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted packet. | 2 | 4.3 | Medium | 2017-01-19 | 2016-11-28 | View | |
21773 | CVE-2016-7257 | The GDI component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Office for Mac 2011, and Office 2016 for Mac allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "GDI Information Disclosure Vulnerability." | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-23 | View | |
22029 | CVE-2016-8291 | Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.54 and 8.55 allows remote attackers to affect confidentiality and integrity via vectors related to Mobile Application Platform. | 2 | 5.8 | Medium | 2017-01-19 | 2016-12-02 | View | |
87821 | CVE-2017-11195 | Pulse Connect Secure 8.3R1 has Reflected XSS in launchHelp.cgi. The helpLaunchPage parameter is reflected in an IFRAME element, if the value contains two quotes. It properly sanitizes quotes and tags, so one cannot simply close the src with a quote and inject after that. However, an attacker can use javascript: or data: to abuse this. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-17 | View |
Page 487 of 17672, showing 5 records out of 88360 total, starting on record 2431, ending on 2435