CVE List

Id CVE No. Status Description Phase Votes Comments Actions
104209  CVE-2017-7389  Candidate  Multiple Cross-Site Scripting (XSS) were discovered in "openeclass Release_3.5.4". The vulnerabilities exist due to insufficient filtration of user-supplied data (meeting_id, user) passed to the "openeclass-master/modules/tc/webconf/webconf.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.  Assigned (20170331)  None (candidate not yet proposed)    View
104210  CVE-2017-7390  Candidate  A Cross-Site Scripting (XSS) was discovered in "SocialNetwork v1.2.1". The vulnerability exists due to insufficient filtration of user-supplied data (mail) passed to the "SocialNetwork-andrea/app/template/pw_forgot.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.  Assigned (20170331)  None (candidate not yet proposed)    View
104211  CVE-2017-7391  Candidate  A Cross-Site Scripting (XSS) was discovered in "Magmi 0.7.22". The vulnerability exists due to insufficient filtration of user-supplied data (prefix) passed to the "magmi-git-master/magmi/web/ajax_gettime.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.  Assigned (20170331)  None (candidate not yet proposed)    View
104212  CVE-2017-7392  Candidate  In TigerVNC 1.7.1 (SSecurityVeNCrypt.cxx SSecurityVeNCrypt::SSecurityVeNCrypt), an unauthenticated client can cause a small memory leak in the server.  Assigned (20170331)  None (candidate not yet proposed)    View
104213  CVE-2017-7393  Candidate  In TigerVNC 1.7.1 (VNCSConnectionST.cxx VNCSConnectionST::fence), an authenticated client can cause a double free, leading to denial of service or potentially code execution.  Assigned (20170331)  None (candidate not yet proposed)    View

Page 689 of 20943, showing 5 records out of 104715 total, starting on record 3441, ending on 3445

Actions