NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
87639 | CVE-2017-10682 | SQL injection vulnerability in the administrative backend in Piwigo through 2.9.1 allows remote users to execute arbitrary SQL commands via the cat_false or cat_true parameter in the comments or status page to cat_options.php. | 2 | 7.5 | High | 2017-07-18 | 2017-07-04 | View | |
87645 | CVE-2017-10688 | In LibTIFF 4.0.8, there is a assertion abort in the TIFFWriteDirectoryTagCheckedLong8Array function in tif_dirwrite.c. A crafted input will lead to a remote denial of service attack. | 2 | 5 | Medium | 2017-07-18 | 2017-07-04 | View | |
87306 | CVE-2017-9356 | Sitecore.NET 7.1 through 7.2 has a Cross Site Scripting Vulnerability via the searchStr parameter to the /Search-Results URI. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-03 | View | |
87334 | CVE-2017-9774 | Remote Code Execution was found in Horde_Image 2.x before 2.5.0 via a crafted GET request. Exploitation requires authentication. | 2 | 6.5 | Medium | 2017-07-18 | 2017-07-03 | View | |
87338 | CVE-2017-9780 | In Flatpak before 0.8.7, a third-party app repository could include malicious apps that contain files with inappropriate permissions, for example setuid or world-writable. The files are deployed with those permissions, which would let a local attacker run the setuid executable or write to the world-writable location. In the case of the system helper component, files deployed as part of the app are owned by root, so in the worst case they could be setuid root. | 2 | 7.2 | High | 2017-07-18 | 2017-07-03 | View |
Page 1320 of 17672, showing 5 records out of 88360 total, starting on record 6596, ending on 6600