NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
87747 | CVE-2017-10970 | Cross-site scripting (XSS) vulnerability in link.php in Cacti 1.1.12 allows remote anonymous users to inject arbitrary web script or HTML via the id parameter, related to the die_html_input_error function in lib/html_validate.php. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-17 | View | |
88003 | CVE-2017-5640 | It was noticed that a malicious process impersonating an Impala daemon in Apache Impala (incubating) 2.7.0 to 2.8.0 could cause Impala daemons to skip authentication checks when Kerberos is enabled (but TLS is not). If the malicious server responds with 'COMPLETE' before the SASL handshake has completed, the client will consider the handshake as completed even though no exchange of credentials has happened. | 2 | 7.5 | High | 2017-07-18 | 2017-07-17 | View | |
88259 | CVE-2017-9897 | XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to a User Mode Write AV starting at Xfpx+0x000000000000dcab. | 2 | 6.8 | Medium | 2017-07-18 | 2017-07-10 | View | |
66244 | CVE-2005-0487 | Cross-site scripting (XSS) vulnerability in index.php for Kayako ESupport 2.3.1, and possibly other versions, allows remote attackers to inject arbitrary HTML and web script via the nav parameter. | 2 | 6.8 | Medium | 2017-07-18 | 2017-07-10 | View | |
66500 | CVE-2005-0750 | The bluez_sock_create function in the Bluetooth stack for Linux kernel 2.4.6 through 2.4.30-rc1 and 2.6 through 2.6.11.5 allows local users to gain privileges via (1) socket or (2) socketpair call with a negative protocol value. | 2 | 7.2 | High | 2017-07-18 | 2017-07-10 | View |
Page 1057 of 17672, showing 5 records out of 88360 total, starting on record 5281, ending on 5285