NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
84861  CVE-2017-7566  MyBB before 1.8.11 allows remote attackers to bypass an SSRF protection mechanism.    Medium  2017-04-27  2017-04-13  View
85373  CVE-2017-2091  Cybozu Garoon 3.0.0 to 4.2.3 allows remote authenticated attackers to bypass access restriction in Phone Messages function to alter the status of phone messages via unspecified vectors.    Medium  2017-05-07  2017-05-03  View
85629  CVE-2016-10349  The archive_le32dec function in archive_endian.h in libarchive 3.2.2 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.    4.3  Medium  2017-05-08  2017-05-05  View
85885  CVE-2017-2799  An exploitable heap corruption vulnerability exists in the AddSst functionality of Antenna House DMC HTMLFilter as used by MarkLogic 8.0-6. A specially crafted XLS file can cause a heap corruption resulting in arbitrary code execution. An attacker can send or provide a malicious XLS file to trigger this vulnerability.    6.8  Medium  2017-06-12  2017-06-06  View
86141  CVE-2017-8930  Multiple cross-site request forgery (CSRF) vulnerabilities in Simple Invoices 2013.1.beta.8 allow remote attackers to hijack the authentication of admins for requests that can (1) create new administrator user accounts and take over the entire application, (2) create regular user accounts, or (3) change configuration parameters such as tax rates and the enable/disable status of PayPal payment modules.    6.8  Medium  2017-05-27  2017-05-25  View

Page 1189 of 17672, showing 5 records out of 88360 total, starting on record 5941, ending on 5945

Actions