NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
84000 | CVE-2016-9243 | HKDF in cryptography before 1.5.2 returns an empty byte-string if used with a length less than algorithm.digest_size. | 2017-03-29 | 2017-03-27 | View | ||||
83999 | CVE-2016-9169 | A reflected XSS vulnerability exists in the web console of the Document Viewer Agent in Novell GroupWise before 2014 R2 Support Pack 1 Hot Patch 2 that may enable a remote attacker to execute JavaScript in the context of a valid user"s browser session by getting the user to click on a specially crafted link. This could lead to session compromise or other browser-based attacks. | 2 | 4.3 | Medium | 2017-03-29 | 2017-03-24 | View | |
83998 | CVE-2016-9168 | A missing X-Frame-Options header in the NDS Utility Monitor in NDSD in Novell eDirectory before 9.0.2 could be used by remote attackers for clickjacking. | 2 | 4.3 | Medium | 2017-03-29 | 2017-03-27 | View | |
83997 | CVE-2016-9167 | NDSD in Novell eDirectory before 9.0.2 did not calculate ACLs on LDAP objects across partition boundaries correctly, which could lead to a privilege escalation by modifying user attributes that would otherwise be filtered by an ACL. | 2 | 5 | Medium | 2017-03-29 | 2017-03-27 | View | |
83996 | CVE-2016-9130 | Revive Adserver before 3.2.3 suffers from Persistent XSS. A vector for persistent XSS attacks via the Revive Adserver user interface exists, requiring a trusted (non-admin) account. The website name wasn"t properly escaped when displayed in the campaign-zone.php script. | 2 | 3.5 | Low | 2017-03-29 | 2017-03-29 | View |
Page 873 of 17672, showing 5 records out of 88360 total, starting on record 4361, ending on 4365