NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
87745 | CVE-2017-10967 | In FineCMS before 2017-07-06, applicationcorecontrollerconfig.php allows XSS in the (1) key_name, (2) key_value, and (3) meaning parameters. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-13 | View | |
88001 | CVE-2017-5528 | Multiple JasperReports Server components contain vulnerabilities which may allow authorized users to perform cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks. The impact of this vulnerability includes the theoretical disclosure of sensitive information. Affects TIBCO JasperReports Server (versions 6.1.1 and below, 6.2.0, 6.2.1, and 6.3.0), TIBCO JasperReports Server Community Edition (versions 6.3.0 and below), TIBCO JasperReports Server for ActiveMatrix BPM (versions 6.2.0 and below), TIBCO Jaspersoft for AWS with Multi-Tenancy (versions 6.2.0 and below), and TIBCO Jaspersoft Reporting and Analytics for AWS (versions 6.2.0 and below). | 2 | 6.8 | Medium | 2017-07-18 | 2017-07-05 | View | |
88257 | CVE-2017-9895 | XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to a Read Access Violation on Control Flow starting at Xfpx!gffGetFormatInfo+0x0000000000020e95. | 2 | 6.8 | Medium | 2017-07-18 | 2017-07-10 | View | |
65986 | CVE-2005-0222 | main.php in Gallery 2.0 Alpha allows remote attackers to gain sensitive information by changing the value of g2_subView parameter, which reveals the path in an error message. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
66242 | CVE-2005-0485 | Cross-site scripting (XSS) vulnerability in comment.php for paNews 2.0b4 for PHP Arena allows remote attackers to inject arbitrary HTML and web script via the showpost parameter. | 2 | 6.8 | Medium | 2017-07-18 | 2017-07-10 | View |
Page 1045 of 17672, showing 5 records out of 88360 total, starting on record 5221, ending on 5225