CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
102437 | CVE-2017-5617 | Candidate | The SVG Salamander (aka svgSalamander) library, when used in a web application, allows remote attackers to conduct server-side request forgery (SSRF) attacks via an xlink:href attribute in an SVG file. | Assigned (20170129) | None (candidate not yet proposed) | View | |
102438 | CVE-2017-5618 | Candidate | GNU screen before 4.5.1 allows local users to modify arbitrary files and consequently gain root privileges by leveraging improper checking of logfile permissions. | Assigned (20170129) | None (candidate not yet proposed) | View | |
102439 | CVE-2017-5619 | Candidate | An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. Attackers can login with the hashed password itself (e.g., from the DB) instead of the valid password string. | Assigned (20170129) | None (candidate not yet proposed) | View | |
102440 | CVE-2017-5620 | Candidate | An XSS issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. Attachments are opened in a new tab instead of getting downloaded. This creates an attack vector of executing code in the domain of the application. | Assigned (20170129) | None (candidate not yet proposed) | View | |
102441 | CVE-2017-5621 | Candidate | An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. XSS can be triggered via malicious HTML in a chat message or the content of a ticket article, when using either the REST API or the WebSocket API. | Assigned (20170129) | None (candidate not yet proposed) | View |
Page 19858 of 20943, showing 5 records out of 104715 total, starting on record 99286, ending on 99290