NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
87745  CVE-2017-10967  In FineCMS before 2017-07-06, applicationcorecontrollerconfig.php allows XSS in the (1) key_name, (2) key_value, and (3) meaning parameters.    4.3  Medium  2017-07-18  2017-07-13  View
88001  CVE-2017-5528  Multiple JasperReports Server components contain vulnerabilities which may allow authorized users to perform cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks. The impact of this vulnerability includes the theoretical disclosure of sensitive information. Affects TIBCO JasperReports Server (versions 6.1.1 and below, 6.2.0, 6.2.1, and 6.3.0), TIBCO JasperReports Server Community Edition (versions 6.3.0 and below), TIBCO JasperReports Server for ActiveMatrix BPM (versions 6.2.0 and below), TIBCO Jaspersoft for AWS with Multi-Tenancy (versions 6.2.0 and below), and TIBCO Jaspersoft Reporting and Analytics for AWS (versions 6.2.0 and below).    6.8  Medium  2017-07-18  2017-07-05  View
88257  CVE-2017-9895  XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to a Read Access Violation on Control Flow starting at Xfpx!gffGetFormatInfo+0x0000000000020e95.    6.8  Medium  2017-07-18  2017-07-10  View
65986  CVE-2005-0222  main.php in Gallery 2.0 Alpha allows remote attackers to gain sensitive information by changing the value of g2_subView parameter, which reveals the path in an error message.    Medium  2017-07-18  2017-07-10  View
66242  CVE-2005-0485  Cross-site scripting (XSS) vulnerability in comment.php for paNews 2.0b4 for PHP Arena allows remote attackers to inject arbitrary HTML and web script via the showpost parameter.    6.8  Medium  2017-07-18  2017-07-10  View

Page 1045 of 17672, showing 5 records out of 88360 total, starting on record 5221, ending on 5225

Actions