NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
84809 | CVE-2017-7361 | Pixie 1.0.4 allows an admin/index.php s=publish&m=static&x= XSS attack. | 2 | 4.3 | Medium | 2017-04-27 | 2017-04-04 | View | |
85065 | CVE-2017-8284 | ** DISPUTED ** The disas_insn function in target/i386/translate.c in QEMU before 2.9.0, when TCG mode without hardware acceleration is used, does not limit the instruction size, which allows local users to gain privileges by creating a modified basic block that injects code into a setuid program, as demonstrated by procmail. NOTE: the vendor has stated this bug does not violate any security guarantees QEMU makes. | 2 | 6.9 | Medium | 2017-05-27 | 2017-05-10 | View | |
85321 | CVE-2016-4892 | Cross-site scripting vulnerability in SetsucoCMS all versions allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 2 | 4.3 | Medium | 2017-05-27 | 2017-05-22 | View | |
85577 | CVE-2017-8454 | Foxit Reader before 8.2.1 and PhantomPDF before 8.2.1 have an out-of-bounds read that allows remote attackers to obtain sensitive information or possibly execute arbitrary code via a crafted font in a PDF document. | 2 | 6.8 | Medium | 2017-05-27 | 2017-05-12 | View | |
85833 | CVE-2017-2502 | An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the CoreAudio component. It allows attackers to bypass intended memory-read restrictions via a crafted app. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-07 | View |
Page 821 of 17672, showing 5 records out of 88360 total, starting on record 4101, ending on 4105