NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
86041 | CVE-2017-7620 | MantisBT before 1.3.11, 2.x before 2.3.3, and 2.4.x before 2.4.1 omits a backslash check in string_api.php and consequently has conflicting interpretations of an initial / substring as introducing either a local pathname or a remote hostname, which leads to (1) arbitrary Permalink Injection via CSRF attacks on a permalink_page.php?url= URI and (2) an open redirect via a login_page.php?return= URI. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-07 | View | |
87577 | CVE-2017-1000038 | WordPress plugin Relevanssi version 3.5.7.1 is vulnerable to stored XSS resulting in attacker being able to execute JavaScript on the affected site | 2017-07-18 | 2017-07-17 | View | ||||
87833 | CVE-2017-11336 | There is a heap-based buffer over-read in the Image::printIFDStructure function in image.cpp in Exiv2 0.26. A Crafted input will lead to a remote denial of service attack. | 2017-07-18 | 2017-07-17 | View | ||||
88089 | CVE-2017-7673 | Apache OpenMeetings 1.0.0 uses not very strong cryptographic storage, captcha is not used in registration and forget password dialogs and auth forms missing brute force protection. | 2017-07-18 | 2017-07-17 | View | ||||
88345 | CVE-2017-7506 | spice versions though 0.13 are vulnerable to out-of-bounds memory access when processing specially crafted messages from authenticated attacker to the spice server resulting into crash and/or server memory leak. | 2017-07-18 | 2017-07-18 | View |
Page 155 of 17672, showing 5 records out of 88360 total, starting on record 771, ending on 775