NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
87639  CVE-2017-10682  SQL injection vulnerability in the administrative backend in Piwigo through 2.9.1 allows remote users to execute arbitrary SQL commands via the cat_false or cat_true parameter in the comments or status page to cat_options.php.    7.5  High  2017-07-18  2017-07-04  View
87645  CVE-2017-10688  In LibTIFF 4.0.8, there is a assertion abort in the TIFFWriteDirectoryTagCheckedLong8Array function in tif_dirwrite.c. A crafted input will lead to a remote denial of service attack.    Medium  2017-07-18  2017-07-04  View
87306  CVE-2017-9356  Sitecore.NET 7.1 through 7.2 has a Cross Site Scripting Vulnerability via the searchStr parameter to the /Search-Results URI.    4.3  Medium  2017-07-18  2017-07-03  View
87334  CVE-2017-9774  Remote Code Execution was found in Horde_Image 2.x before 2.5.0 via a crafted GET request. Exploitation requires authentication.    6.5  Medium  2017-07-18  2017-07-03  View
87338  CVE-2017-9780  In Flatpak before 0.8.7, a third-party app repository could include malicious apps that contain files with inappropriate permissions, for example setuid or world-writable. The files are deployed with those permissions, which would let a local attacker run the setuid executable or write to the world-writable location. In the case of the system helper component, files deployed as part of the app are owned by root, so in the worst case they could be setuid root.    7.2  High  2017-07-18  2017-07-03  View

Page 1320 of 17672, showing 5 records out of 88360 total, starting on record 6596, ending on 6600

Actions