NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
7111  CVE-2017-5223  An issue was discovered in PHPMailer before 5.2.22. PHPMailer's msgHTML method applies transformations to an HTML document to make it usable as an email message body. One of the transformations is to convert relative image URLs into attachments using a script-provided base directory. If no base directory is provided, it resolves to /, meaning that relative image URLs get treated as absolute local file paths and added as attachments. To form a remote vulnerability, the msgHTML method must be called, passed an unfiltered, user-supplied HTML document, and must not set a base directory.    2.1  Low  2017-01-19  2017-01-18  View
7112  CVE-2017-5225  LibTIFF version 4.0.7 is vulnerable to a heap buffer overflow in the tools/tiffcp resulting in DoS or code execution via a crafted BitsPerSample value.    7.5  High  2017-07-18  2017-07-17  View
7113  CVE-2017-5340  Zend/zend_hash.c in PHP before 7.0.15 and 7.1.x before 7.1.1 mishandles certain cases that require large array allocations, which allows remote attackers to execute arbitrary code or cause a denial of service (integer overflow, uninitialized memory access, and use of arbitrary destructor function pointers) via crafted serialized data.    7.5  High  2017-01-19  2017-01-12  View
7114  CVE-2017-5345  SQL injection vulnerability in inc/lib/Control/Ajax/tags-ajax.control.php in GeniXCMS 0.0.8 allows remote authenticated editors to execute arbitrary SQL commands via the term parameter to the default URI.    6.5  Medium  2017-01-30  2017-01-27  View
7115  CVE-2017-5346  SQL injection vulnerability in inc/lib/Control/Backend/posts.control.php in GeniXCMS 0.0.8 allows remote authenticated administrators to execute arbitrary SQL commands via the id parameter to gxadmin/index.php.    6.5  Medium  2017-06-03  2017-05-29  View

Page 1423 of 17672, showing 5 records out of 88360 total, starting on record 7111, ending on 7115

Actions