CVE List

Id CVE No. Status Description Phase Votes Comments Actions
104445  CVE-2017-7625  Candidate  In Fiyo CMS 2.x through 2.0.7, attackers may upload a webshell via the content parameter to "/dapur/apps/app_theme/libs/save_file.php" and then execute code.  Assigned (20170410)  None (candidate not yet proposed)    View
104444  CVE-2017-7624  Candidate  The iw_read_bmp_file function in imagew-bmp.c in libimageworsener.a in ImageWorsener 1.3.0 allows remote attackers to consume an amount of available memory via a crafted file.  Assigned (20170410)  None (candidate not yet proposed)    View
104443  CVE-2017-7623  Candidate  The iwmiffr_convert_row32 function in imagew-miff.c in libimageworsener.a in ImageWorsener 1.3.0 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file.  Assigned (20170410)  None (candidate not yet proposed)    View
104442  CVE-2017-7622  Candidate  dde-daemon, the daemon process of DDE (Deepin Desktop Environment) 15.0 through 15.3, runs with root privileges and hardly does anything to identify the user who calls the function through D-Bus. Anybody can change the grub config, even to append some arguments to make a backdoor or privilege escalation, by calling DoWriteGrubSettings() provided by dde-daemon.  Assigned (20170410)  None (candidate not yet proposed)    View
104441  CVE-2017-7621  Candidate  Cross Site Scripting Vulnerability in core-eMLi in AuroMeera Technometrix Pvt. Ltd. eMLi V1.0 allows an Attacker to send malicious code, generally in the form of a browser-side script, to a different end user via the page parameter to code/student_portal/home.php. The affected versions are eMLi School Management 1.0, eMLi College Campus Management 1.0, and eMLi University Management 1.0.  Assigned (20170410)  None (candidate not yet proposed)    View

Page 55 of 20943, showing 5 records out of 104715 total, starting on record 271, ending on 275

Actions