NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 87750 | CVE-2017-10973 | In FineCMS before 2017-07-06, application/lib/ajax/get_image_data.php has SSRF, related to requests for non-image files with a modified HTTP Host header. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-17 | View | |
| 88006 | CVE-2017-5944 | The dashboard subscription interface in Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 might allow remote authenticated users with certain privileges to execute arbitrary code via a crafted saved search name. | 2 | 6.5 | Medium | 2017-07-18 | 2017-07-07 | View | |
| 22726 | CVE-2015-0227 | Apache WSS4J before 1.6.17 and 2.x before 2.0.2 allows remote attackers to bypass the requireSignedEncryptedDataElements configuration via a vectors related to "wrapping attacks." | 2 | 5 | Medium | 2017-01-19 | 2015-07-09 | View | |
| 88262 | CVE-2017-9900 | XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to Data from Faulting Address controls Code Flow starting at Xfpx!gffGetFormatInfo+0x000000000002e385. | 2 | 6.8 | Medium | 2017-07-18 | 2017-07-10 | View | |
| 23238 | CVE-2015-0798 | The Reader mode feature in Mozilla Firefox before 37.0.1 on Android, and Desktop Firefox pre-release, does not properly handle privileged URLs, which makes it easier for remote attackers to execute arbitrary JavaScript code with chrome privileges by leveraging the ability to bypass the Same Origin Policy. | 2 | 5 | Medium | 2017-01-19 | 2016-12-07 | View |
Page 15628 of 17672, showing 5 records out of 88360 total, starting on record 78136, ending on 78140