CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
102493 | CVE-2017-5673 | Candidate | In the Kunena extension 5.0.2 through 5.0.4 for Joomla!, the forum message subject (aka topic subject) accepts JavaScript, leading to XSS. Six files are affected: crypsis/layouts/message/item/default.php, crypsis/layouts/message/item/top/default.php, crypsis/layouts/message/item/bottom/default.php, crypsisb3/layouts/message/item/default.php, crypsisb3/layouts/message/item/top/default.php, and crypsisb3/layouts/message/item/bottom/default.php. This is fixed in 5.0.5. | Assigned (20170131) | None (candidate not yet proposed) | View | |
102494 | CVE-2017-5674 | Candidate | A vulnerability in a custom-built GoAhead web server used on Foscam, Vstarcam, and multiple white-label IP camera models allows an attacker to craft a malformed HTTP ("GET system.ini HTTP/1.1 " - note the lack of "/" in the path field of the request) request that will disclose the configuration file with the login password. | Assigned (20170131) | None (candidate not yet proposed) | View | |
102495 | CVE-2017-5675 | Candidate | A command-injection vulnerability exists in a web application on a custom-built GoAhead web server used on Foscam, Vstarcam, and multiple white-label IP camera models. The mail-sending form in the mail.htm page allows an attacker to inject a command into the receiver1 field in the form; it will be executed with root privileges. | Assigned (20170131) | None (candidate not yet proposed) | View | |
87696 | CVE-2016-10187 | Candidate | The E-book viewer in calibre before 2.75 allows remote attackers to read arbitrary files via a crafted epub file with JavaScript. | Assigned (20170131) | None (candidate not yet proposed) | View | |
87697 | CVE-2016-10188 | Candidate | Use-after-free vulnerability in bitlbee-libpurple before 3.5 allows remote servers to cause a denial of service (crash) or possibly execute arbitrary code by causing a file transfer connection to expire. | Assigned (20170131) | None (candidate not yet proposed) | View |
Page 19872 of 20943, showing 5 records out of 104715 total, starting on record 99356, ending on 99360