NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
87750  CVE-2017-10973  In FineCMS before 2017-07-06, application/lib/ajax/get_image_data.php has SSRF, related to requests for non-image files with a modified HTTP Host header.    4.3  Medium  2017-07-18  2017-07-17  View
88006  CVE-2017-5944  The dashboard subscription interface in Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 might allow remote authenticated users with certain privileges to execute arbitrary code via a crafted saved search name.    6.5  Medium  2017-07-18  2017-07-07  View
22726  CVE-2015-0227  Apache WSS4J before 1.6.17 and 2.x before 2.0.2 allows remote attackers to bypass the requireSignedEncryptedDataElements configuration via a vectors related to "wrapping attacks."    Medium  2017-01-19  2015-07-09  View
88262  CVE-2017-9900  XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to Data from Faulting Address controls Code Flow starting at Xfpx!gffGetFormatInfo+0x000000000002e385.    6.8  Medium  2017-07-18  2017-07-10  View
23238  CVE-2015-0798  The Reader mode feature in Mozilla Firefox before 37.0.1 on Android, and Desktop Firefox pre-release, does not properly handle privileged URLs, which makes it easier for remote attackers to execute arbitrary JavaScript code with chrome privileges by leveraging the ability to bypass the Same Origin Policy.    Medium  2017-01-19  2016-12-07  View

Page 15628 of 17672, showing 5 records out of 88360 total, starting on record 78136, ending on 78140

Actions