NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
84225  CVE-2017-1170  IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 8.0 could allow a local user to hijack a user's session. IBM X-Force ID: 123230.    4.6  Medium  2017-07-18  2017-07-10  View
84481  CVE-2017-3469  Vulnerability in the MySQL Workbench component of Oracle MySQL (subcomponent: Workbench: Security : Encryption). Supported versions that are affected are 6.3.8 and earlier. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Workbench. Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Workbench accessible data. CVSS 3.0 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).    4.3  Medium  2017-07-18  2017-07-10  View
84737  CVE-2017-6441  ** DISPUTED ** The _zval_get_long_func_ex in Zend/zend_operators.c in PHP 7.1.2 allows attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted use of declare(ticks= in a PHP script. NOTE: the vendor disputes the classification of this as a vulnerability, stating Please do not request CVEs for ordinary bugs. CVEs are relevant for security issues only.    Medium  2017-04-27  2017-04-10  View
84993  CVE-2017-7951  WonderCMS before 2.0.3 has CSRF because of lack of a token in an unspecified context.    6.8  Medium  2017-04-27  2017-04-24  View
85505  CVE-2017-8081  Poor cryptographic salt initialization in admin/inc/template_functions.php in GetSimple CMS 3.3.13 allows a network attacker to escalate privileges to an arbitrary user or conduct CSRF attacks via calculation of a session cookie or CSRF nonce.    6.8  Medium  2017-05-27  2017-05-11  View

Page 15484 of 17672, showing 5 records out of 88360 total, starting on record 77416, ending on 77420

Actions