NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
86685  CVE-2017-9439  In ImageMagick 7.0.5-5, a memory leak was found in the function ReadPDBImage in coders/pdb.c, which allows attackers to cause a denial of service via a crafted file.    4.3  Medium  2017-06-12  2017-06-09  View
86686  CVE-2017-9440  In ImageMagick 7.0.5-5, a memory leak was found in the function ReadPSDChannel in coders/psd.c, which allows attackers to cause a denial of service via a crafted file.    4.3  Medium  2017-06-12  2017-06-09  View
86688  CVE-2017-9442  ** DISPUTED ** BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary code by uploading a crafted package containing a PHP web shell, related to extraction of a ZIP archive to filename patterns such as cache/package/xxx/yyy.php. This issue exists in coreadminmodulesdeveloperextensionsinstallunpack.php and coreadminmodulesdeveloperpackagesinstallunpack.php. NOTE: the vendor states You must implicitly trust any package or extension you install as they all have the ability to write PHP files.    6.5  Medium  2017-06-12  2017-06-09  View
86689  CVE-2017-9443  ** DISPUTED ** BigTree CMS through 4.2.18 allows remote authenticated users to conduct SQL injection attacks via a crafted tables object in manifest.json in an uploaded package. This issue exists in coreadminmodulesdeveloperextensionsinstallprocess.php and coreadminmodulesdeveloperpackagesinstallprocess.php. NOTE: the vendor states You must implicitly trust any package or extension you install as they all have the ability to write PHP files.    6.5  Medium  2017-06-12  2017-06-09  View
86694  CVE-2017-9452  Cross-site scripting (XSS) vulnerability in admin.php in Piwigo 2.9.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the page parameter.    3.5  Low  2017-06-12  2017-06-09  View

Page 1498 of 17672, showing 5 records out of 88360 total, starting on record 7486, ending on 7490

Actions