CVE List

Id CVE No. Status Description Phase Votes Comments Actions
102440  CVE-2017-5620  Candidate  An XSS issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. Attachments are opened in a new tab instead of getting downloaded. This creates an attack vector of executing code in the domain of the application.  Assigned (20170129)  None (candidate not yet proposed)    View
102439  CVE-2017-5619  Candidate  An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. Attackers can login with the hashed password itself (e.g., from the DB) instead of the valid password string.  Assigned (20170129)  None (candidate not yet proposed)    View
102438  CVE-2017-5618  Candidate  GNU screen before 4.5.1 allows local users to modify arbitrary files and consequently gain root privileges by leveraging improper checking of logfile permissions.  Assigned (20170129)  None (candidate not yet proposed)    View
102437  CVE-2017-5617  Candidate  The SVG Salamander (aka svgSalamander) library, when used in a web application, allows remote attackers to conduct server-side request forgery (SSRF) attacks via an xlink:href attribute in an SVG file.  Assigned (20170129)  None (candidate not yet proposed)    View
102436  CVE-2017-5616  Candidate  Cross-site scripting (XSS) vulnerability in cgiemail and cgiecho allows remote attackers to inject arbitrary web script or HTML via the addendum parameter.  Assigned (20170128)  None (candidate not yet proposed)    View

Page 456 of 20943, showing 5 records out of 104715 total, starting on record 2276, ending on 2280

Actions