CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
102310 | CVE-2017-5490 | Candidate | Cross-site scripting (XSS) vulnerability in the theme-name fallback functionality in wp-includes/class-wp-theme.php in WordPress before 4.7.1 allows remote attackers to inject arbitrary web script or HTML via a crafted directory name of a theme, related to wp-admin/includes/class-theme-installer-skin.php. | Assigned (20170114) | None (candidate not yet proposed) | View | |
102309 | CVE-2017-5489 | Candidate | Cross-site request forgery (CSRF) vulnerability in WordPress before 4.7.1 allows remote attackers to hijack the authentication of unspecified victims via vectors involving a Flash file upload. | Assigned (20170114) | None (candidate not yet proposed) | View | |
102308 | CVE-2017-5488 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/update-core.php in WordPress before 4.7.1 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) version header of a plugin. | Assigned (20170114) | None (candidate not yet proposed) | View | |
102307 | CVE-2017-5487 | Candidate | wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not properly restrict listings of post authors, which allows remote attackers to obtain sensitive information via a wp-json/wp/v2/users request. | Assigned (20170114) | None (candidate not yet proposed) | View | |
102306 | CVE-2017-5486 | Candidate | The ISO CLNS parser in tcpdump before 4.9.0 has a buffer overflow in print-isoclns.c:clnp_print(). | Assigned (20170114) | None (candidate not yet proposed) | View |
Page 482 of 20943, showing 5 records out of 104715 total, starting on record 2406, ending on 2410