CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
102440 | CVE-2017-5620 | Candidate | An XSS issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. Attachments are opened in a new tab instead of getting downloaded. This creates an attack vector of executing code in the domain of the application. | Assigned (20170129) | None (candidate not yet proposed) | View | |
102439 | CVE-2017-5619 | Candidate | An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. Attackers can login with the hashed password itself (e.g., from the DB) instead of the valid password string. | Assigned (20170129) | None (candidate not yet proposed) | View | |
102438 | CVE-2017-5618 | Candidate | GNU screen before 4.5.1 allows local users to modify arbitrary files and consequently gain root privileges by leveraging improper checking of logfile permissions. | Assigned (20170129) | None (candidate not yet proposed) | View | |
102437 | CVE-2017-5617 | Candidate | The SVG Salamander (aka svgSalamander) library, when used in a web application, allows remote attackers to conduct server-side request forgery (SSRF) attacks via an xlink:href attribute in an SVG file. | Assigned (20170129) | None (candidate not yet proposed) | View | |
102436 | CVE-2017-5616 | Candidate | Cross-site scripting (XSS) vulnerability in cgiemail and cgiecho allows remote attackers to inject arbitrary web script or HTML via the addendum parameter. | Assigned (20170128) | None (candidate not yet proposed) | View |
Page 456 of 20943, showing 5 records out of 104715 total, starting on record 2276, ending on 2280