NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
84861 | CVE-2017-7566 | MyBB before 1.8.11 allows remote attackers to bypass an SSRF protection mechanism. | 2 | 4 | Medium | 2017-04-27 | 2017-04-13 | View | |
85373 | CVE-2017-2091 | Cybozu Garoon 3.0.0 to 4.2.3 allows remote authenticated attackers to bypass access restriction in Phone Messages function to alter the status of phone messages via unspecified vectors. | 2 | 4 | Medium | 2017-05-07 | 2017-05-03 | View | |
85629 | CVE-2016-10349 | The archive_le32dec function in archive_endian.h in libarchive 3.2.2 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file. | 2 | 4.3 | Medium | 2017-05-08 | 2017-05-05 | View | |
85885 | CVE-2017-2799 | An exploitable heap corruption vulnerability exists in the AddSst functionality of Antenna House DMC HTMLFilter as used by MarkLogic 8.0-6. A specially crafted XLS file can cause a heap corruption resulting in arbitrary code execution. An attacker can send or provide a malicious XLS file to trigger this vulnerability. | 2 | 6.8 | Medium | 2017-06-12 | 2017-06-06 | View | |
86141 | CVE-2017-8930 | Multiple cross-site request forgery (CSRF) vulnerabilities in Simple Invoices 2013.1.beta.8 allow remote attackers to hijack the authentication of admins for requests that can (1) create new administrator user accounts and take over the entire application, (2) create regular user accounts, or (3) change configuration parameters such as tax rates and the enable/disable status of PayPal payment modules. | 2 | 6.8 | Medium | 2017-05-27 | 2017-05-25 | View |
Page 1189 of 17672, showing 5 records out of 88360 total, starting on record 5941, ending on 5945