NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 84835 | CVE-2017-7402 | Pixie 1.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via the POST data in an admin/index.php?s=publish&x=filemanager request for a filename with a double extension, such as a .jpg.php file with Content-Type of image/jpeg. | 2 | 7.5 | High | 2017-04-27 | 2017-04-10 | View | |
| 84846 | CVE-2017-7446 | HelpDEZk 1.1.1 has CSRF in admin/home#/person/ with an impact of obtaining admin privileges. | 2 | 6.8 | Medium | 2017-04-27 | 2017-04-10 | View | |
| 84847 | CVE-2017-7447 | HelpDEZk 1.1.1 has CSRF in admin/home#/logos/ with an impact of remote execution of arbitrary PHP code. | 2 | 6.8 | Medium | 2017-04-27 | 2017-04-10 | View | |
| 84689 | CVE-2017-5642 | During installation of Ambari 2.4.0 through 2.4.2, Ambari Server artifacts are not created with proper ACLs. | 2 | 7.5 | High | 2017-04-27 | 2017-04-10 | View | |
| 84712 | CVE-2017-5949 | JavaScriptCore in WebKit, as distributed in Safari Technology Preview Release 22, allows remote attackers to cause a denial of service (heap-based out-of-bounds write and application crash) or possibly have unspecified other impact via crafted JavaScript code that triggers access to red-zone memory locations, related to jit/ThunkGenerators.cpp, llint/LowLevelInterpreter32_64.asm, and llint/LowLevelInterpreter64.asm. | 2 | 7.5 | High | 2017-04-27 | 2017-04-10 | View |
Page 15824 of 17672, showing 5 records out of 88360 total, starting on record 79116, ending on 79120