NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
87409  CVE-2017-9836  Cross-site scripting (XSS) vulnerability in Piwigo 2.9.1 allows remote authenticated administrators to inject arbitrary web script or HTML via the virtual_name parameter to /admin.php (i.e., creating a virtual album).    3.5  Low  2017-06-28  2017-06-27  View
87410  CVE-2017-9837  The ws_session_logout function in Piwigo 2.9.1 and earlier does not properly delete user login cookies, which allows remote attackers to gain access via cookie reuse.    7.5  High  2017-06-28  2017-06-27  View
87173  CVE-2015-4596  Lenovo Mouse Suite before 6.73 allows local users to run arbitrary code with administrator privileges.    4.6  Medium  2017-06-28  2017-06-28  View
87174  CVE-2015-7732  The Avira Mobile Security app before 1.5.11 for iOS sends sensitive login information in cleartext.    Medium  2017-06-28  2017-06-28  View
85640  CVE-2016-6877  ** DISPUTED ** Citrix XenMobile Server before 10.5.0.24 allows man-in-the-middle attackers to trigger HTTP 302 redirections via vectors involving the HTTP Host header and a cached page. NOTE: the vendor reports "our internal analysis of this issue concluded that this was not a valid vulnerability" because an exploitation scenario would involve a man-in-the-middle attack against a TLS session.    2.6  Low  2017-06-28  2017-06-26  View

Page 1403 of 17672, showing 5 records out of 88360 total, starting on record 7011, ending on 7015

Actions