NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
86635 | CVE-2017-7314 | An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1. When going to the /TabId/275 URI, while creating a new role, a list of database tables and their columns is available. | 2 | 5 | Medium | 2017-06-17 | 2017-06-14 | View | |
86642 | CVE-2017-8083 | CompuLab Intense PC and MintBox 2 devices with BIOS before 2017-05-21 do not use the CloseMnf protection mechanism for write protection of flash memory regions, which allows local users to install a firmware rootkit by leveraging administrative privileges. | 2 | 7.2 | High | 2017-06-17 | 2017-06-14 | View | |
86670 | CVE-2017-9332 | The smarty_self function in modules/module_smarty.php in PivotX 2.3.11 mishandles the URI, allowing XSS via vectors involving quotes in the self Smarty tag. | 2 | 4.3 | Medium | 2017-06-17 | 2017-06-14 | View | |
86697 | CVE-2017-9465 | The yr_arena_write_data function in YARA 3.6.1 allows remote attackers to cause a denial of service (buffer over-read and application crash) or obtain sensitive information from process memory via a crafted file that is mishandled in the yr_re_fast_exec function in libyara/re.c and the _yr_scan_match_callback function in libyara/scan.c. | 2 | 5.8 | Medium | 2017-06-17 | 2017-06-14 | View | |
86708 | CVE-2017-9516 | Craft CMS before 2.6.2982 allows for a potential XSS attack vector by uploading a malicious SVG file. | 2 | 3.5 | Low | 2017-06-17 | 2017-06-14 | View |
Page 1475 of 17672, showing 5 records out of 88360 total, starting on record 7371, ending on 7375