NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
56311 | CVE-2007-4180 | ** DISPUTED ** Directory traversal vulnerability in data/inc/theme.php in Pluck 4.3, when register_globals is enabled, allows remote attackers to read arbitrary local files via a .. (dot dot) in the file parameter. NOTE: CVE and a reliable third party dispute this vulnerability because the code uses a fixed argument when invoking fputs, which cannot be used to read files. | 2 | 5 | Medium | 2017-06-23 | 2017-06-21 | View | |
87050 | CVE-2017-8509 | A remote code execution vulnerability exists in Microsoft Office when the software fails to properly handle objects in memory, aka Office Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2017-8510, CVE-2017-8511, CVE-2017-8512, CVE-2017-0260, and CVE-2017-8506. | 2 | 9.3 | High | 2017-06-23 | 2017-06-20 | View | |
87087 | CVE-2017-9373 | Memory leak in QEMU (aka Quick Emulator), when built with IDE AHCI Emulation support, allows local guest OS privileged users to cause a denial of service (memory consumption) by repeatedly hot-unplugging the AHCI device. | 2 | 1.9 | Low | 2017-06-23 | 2017-06-20 | View | |
87089 | CVE-2017-9375 | QEMU (aka Quick Emulator), when built with USB xHCI controller emulator support, allows local guest OS privileged users to cause a denial of service (infinite recursive call) via vectors involving control transfer descriptors sequencing. | 2 | 1.9 | Low | 2017-06-23 | 2017-06-20 | View | |
87091 | CVE-2017-9429 | SQL injection vulnerability in the Event List plugin 0.7.8 for WordPress allows an authenticated user to execute arbitrary SQL commands via the id parameter to wp-admin/admin.php. | 2 | 6.5 | Medium | 2017-06-23 | 2017-06-20 | View |
Page 1436 of 17672, showing 5 records out of 88360 total, starting on record 7176, ending on 7180