NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
84835  CVE-2017-7402  Pixie 1.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via the POST data in an admin/index.php?s=publish&x=filemanager request for a filename with a double extension, such as a .jpg.php file with Content-Type of image/jpeg.    7.5  High  2017-04-27  2017-04-10  View
84846  CVE-2017-7446  HelpDEZk 1.1.1 has CSRF in admin/home#/person/ with an impact of obtaining admin privileges.    6.8  Medium  2017-04-27  2017-04-10  View
84847  CVE-2017-7447  HelpDEZk 1.1.1 has CSRF in admin/home#/logos/ with an impact of remote execution of arbitrary PHP code.    6.8  Medium  2017-04-27  2017-04-10  View
84689  CVE-2017-5642  During installation of Ambari 2.4.0 through 2.4.2, Ambari Server artifacts are not created with proper ACLs.    7.5  High  2017-04-27  2017-04-10  View
84712  CVE-2017-5949  JavaScriptCore in WebKit, as distributed in Safari Technology Preview Release 22, allows remote attackers to cause a denial of service (heap-based out-of-bounds write and application crash) or possibly have unspecified other impact via crafted JavaScript code that triggers access to red-zone memory locations, related to jit/ThunkGenerators.cpp, llint/LowLevelInterpreter32_64.asm, and llint/LowLevelInterpreter64.asm.    7.5  High  2017-04-27  2017-04-10  View

Page 15824 of 17672, showing 5 records out of 88360 total, starting on record 79116, ending on 79120

Actions