NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
84790 | CVE-2017-7290 | SQL injection vulnerability in XOOPS 2.5.7.2 and other versions before 2.5.8.1 allows remote authenticated administrators to execute arbitrary SQL commands via the url parameter to findusers.php. An example attack uses into outfile to create a backdoor program. | 2 | 6.5 | Medium | 2017-04-27 | 2017-04-03 | View | |
84061 | CVE-2017-7310 | A buffer overflow vulnerability in Import Command in Sync Breeze Enterprise Client 9.5.16, Disk Sorter Enterprise Client 9.5.12, and DiskBoss Enterprise Client 7.8.16 allows attackers to execute arbitrary code via a crafted XML file containing a long name attribute of a classify element. | 2 | 6.8 | Medium | 2017-04-27 | 2017-04-03 | View | |
83831 | CVE-2017-7224 | The find_nearest_line function in objdump in GNU Binutils 2.28 is vulnerable to an invalid write (of size 1) while disassembling a corrupt binary that contains an empty function name, leading to a program crash. | 2 | 4.3 | Medium | 2017-04-27 | 2017-04-03 | View | |
83832 | CVE-2017-7225 | The find_nearest_line function in addr2line in GNU Binutils 2.28 does not handle the case where the main file name and the directory name are both empty, triggering a NULL pointer dereference and an invalid write, and leading to a program crash. | 2 | 5 | Medium | 2017-04-27 | 2017-04-03 | View | |
83348 | CVE-2017-6436 | The parse_string_node function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (memory allocation error) via a crafted plist file. | 2 | 1.9 | Low | 2017-04-27 | 2017-04-03 | View |
Page 15810 of 17672, showing 5 records out of 88360 total, starting on record 79046, ending on 79050