NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
88200 | CVE-2017-8932 | A bug in the standard library ScalarMult implementation of curve P-256 for amd64 architectures in Go before 1.7.6 and 1.8.x before 1.8.2 causes incorrect results to be generated for specific input points. An adaptive attack can be mounted to progressively extract the scalar input to ScalarMult by submitting crafted points and observing failures to the derive correct output. This leads to a full key recovery attack against static ECDH, as used in popular JWT libraries. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-17 | View | |
86141 | CVE-2017-8930 | Multiple cross-site request forgery (CSRF) vulnerabilities in Simple Invoices 2013.1.beta.8 allow remote attackers to hijack the authentication of admins for requests that can (1) create new administrator user accounts and take over the entire application, (2) create regular user accounts, or (3) change configuration parameters such as tax rates and the enable/disable status of PayPal payment modules. | 2 | 6.8 | Medium | 2017-05-27 | 2017-05-25 | View | |
86140 | CVE-2017-8929 | The sized_string_cmp function in libyara/sizedstr.c in YARA 3.5.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted rule. | 2 | 5 | Medium | 2017-05-27 | 2017-05-23 | View | |
86139 | CVE-2017-8928 | mailcow 0.14, as used in mailcow: dockerized and other products, has CSRF. | 2 | 6.8 | Medium | 2017-05-27 | 2017-05-23 | View | |
86138 | CVE-2017-8927 | Buffer overflow in Larson VizEx Reader 9.7.5 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .tif file. | 2 | 6.8 | Medium | 2017-05-27 | 2017-05-24 | View |
Page 117 of 17672, showing 5 records out of 88360 total, starting on record 581, ending on 585