CVE List

Id CVE No. Status Description Phase Votes Comments Actions
102919  CVE-2017-6099  Candidate  Cross-site scripting (XSS) vulnerability in GetAuthDetails.html.php in PayPal PHP Merchant SDK (aka merchant-sdk-php) 3.9.1 allows remote attackers to inject arbitrary web script or HTML via the token parameter.  Assigned (20170218)  None (candidate not yet proposed)    View
87740  CVE-2016-10227  Candidate  Zyxel USG50 Security Appliance and NWA3560-N Access Point allow remote attackers to cause a denial of service (CPU consumption) via a flood of ICMPv4 Port Unreachable packets.  Assigned (20170218)  None (candidate not yet proposed)    View
102897  CVE-2017-6077  Candidate  ping.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ping_IPAddr field of an HTTP POST request.  Assigned (20170218)  None (candidate not yet proposed)    View
102898  CVE-2017-6078  Candidate  FastStone MaxView 3.0 and 3.1 allows user-assisted attackers to cause a denial of service (application crash) via a malformed BMP image with a crafted biSize field in the BITMAPINFOHEADER section.  Assigned (20170218)  None (candidate not yet proposed)    View
102899  CVE-2017-6079  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170218)  None (candidate not yet proposed)    View

Page 979 of 20943, showing 5 records out of 104715 total, starting on record 4891, ending on 4895

Actions