CVE List

Id CVE No. Status Description Phase Votes Comments Actions
104129  CVE-2017-7309  Candidate  A cross-site scripting (XSS) vulnerability in the MantisBT Configuration Report page (adm_config_report.php) allows remote attackers to inject arbitrary code (if CSP settings permit it) through a crafted "config_option" parameter. This is fixed in 1.3.9, 2.1.3, and 2.2.3.  Assigned (20170329)  None (candidate not yet proposed)    View
104130  CVE-2017-7310  Candidate  A buffer overflow vulnerability in Import Command in Sync Breeze Enterprise Client 9.5.16, Disk Sorter Enterprise Client 9.5.12, and DiskBoss Enterprise Client 7.8.16 allows attackers to execute arbitrary code via a crafted XML file containing a long name attribute of a classify element.  Assigned (20170329)  None (candidate not yet proposed)    View
104131  CVE-2017-7311  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170329)  None (candidate not yet proposed)    View
104132  CVE-2017-7312  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170329)  None (candidate not yet proposed)    View
104133  CVE-2017-7313  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170329)  None (candidate not yet proposed)    View

Page 705 of 20943, showing 5 records out of 104715 total, starting on record 3521, ending on 3525

Actions