NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
83190 | CVE-2017-5228 | All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter stdapi Dir.download() function. By using a specially-crafted build of Meterpreter, it is possible to write to an arbitrary directory on the Metasploit console with the permissions of the running Metasploit instance. | 2 | 5.1 | Medium | 2017-03-29 | 2017-03-20 | View | |
83189 | CVE-2017-5197 | There is XSS in SilverStripe CMS before 3.4.4 and 3.5.x before 3.5.2. The attack vector is a page name. An example payload is a crafted JavaScript event handler within a malformed SVG element. | 2 | 4.3 | Medium | 2017-03-18 | 2017-03-07 | View | |
83188 | CVE-2017-5196 | Irssi 0.8.18 before 0.8.21 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via vectors involving strings that are not UTF8. | 2 | 5 | Medium | 2017-07-18 | 2017-06-30 | View | |
83187 | CVE-2017-5195 | Irssi 0.8.17 before 0.8.21 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted ANSI x8 color code. | 2 | 5 | Medium | 2017-07-18 | 2017-06-30 | View | |
83186 | CVE-2017-5194 | Use-after-free vulnerability in Irssi before 0.8.21 allows remote attackers to cause a denial of service (crash) via an invalid nick message. | 2 | 5 | Medium | 2017-07-18 | 2017-06-30 | View |
Page 1035 of 17672, showing 5 records out of 88360 total, starting on record 5171, ending on 5175