NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
86041  CVE-2017-7620  MantisBT before 1.3.11, 2.x before 2.3.3, and 2.4.x before 2.4.1 omits a backslash check in string_api.php and consequently has conflicting interpretations of an initial / substring as introducing either a local pathname or a remote hostname, which leads to (1) arbitrary Permalink Injection via CSRF attacks on a permalink_page.php?url= URI and (2) an open redirect via a login_page.php?return= URI.    4.3  Medium  2017-07-18  2017-07-07  View
87577  CVE-2017-1000038  WordPress plugin Relevanssi version 3.5.7.1 is vulnerable to stored XSS resulting in attacker being able to execute JavaScript on the affected site          2017-07-18  2017-07-17  View
87833  CVE-2017-11336  There is a heap-based buffer over-read in the Image::printIFDStructure function in image.cpp in Exiv2 0.26. A Crafted input will lead to a remote denial of service attack.          2017-07-18  2017-07-17  View
88089  CVE-2017-7673  Apache OpenMeetings 1.0.0 uses not very strong cryptographic storage, captcha is not used in registration and forget password dialogs and auth forms missing brute force protection.          2017-07-18  2017-07-17  View
88345  CVE-2017-7506  spice versions though 0.13 are vulnerable to out-of-bounds memory access when processing specially crafted messages from authenticated attacker to the spice server resulting into crash and/or server memory leak.          2017-07-18  2017-07-18  View

Page 155 of 17672, showing 5 records out of 88360 total, starting on record 771, ending on 775

Actions