NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
85525 | CVE-2017-8342 | Radicale before 1.1.2 and 2.x before 2.0.0rc2 is prone to timing oracles and simple brute-force attacks when using the htpasswd authentication method. | 2 | 4.3 | Medium | 2017-05-27 | 2017-05-11 | View | |
20501 | CVE-2016-5162 | The AllowCrossRendererResourceLoad function in extensions/browser/url_request_util.cc in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux does not properly use an extension"s manifest.json web_accessible_resources field for restrictions on IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks, and trick users into changing extension settings, via a crafted web site, a different vulnerability than CVE-2016-5160. | 2 | 4.3 | Medium | 2017-01-19 | 2016-11-28 | View | |
20757 | CVE-2016-5514 | Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to ExportServlet. | 2 | 6.5 | Medium | 2017-01-19 | 2016-11-28 | View | |
86293 | CVE-2017-9204 | The iw_get_ui16le function in imagew-util.c:405:23 in libimageworsener.a in ImageWorsener 1.3.1 allows remote attackers to cause a denial of service (invalid read and SEGV) via a crafted image, related to imagew-jpeg.c. | 2 | 4.3 | Medium | 2017-06-03 | 2017-05-30 | View | |
21269 | CVE-2016-6512 | epan/dissectors/packet-wap.c in Wireshark 2.x before 2.0.5 omits an overflow check in the tvb_get_guintvar function, which allows remote attackers to cause a denial of service (infinite loop) via a crafted packet, related to the MMSE, WAP, WBXML, and WSP dissectors. | 2 | 4.3 | Medium | 2017-01-19 | 2016-11-28 | View |
Page 771 of 17672, showing 5 records out of 88360 total, starting on record 3851, ending on 3855