NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
84863  CVE-2017-7570  PivotX 2.3.11 allows remote authenticated Advanced users to execute arbitrary PHP code by performing an upload with a safe file extension (such as .jpg) and then invoking the duplicate function to change to the .php extension.    6.5  Medium  2017-04-27  2017-04-13  View
84872  CVE-2017-7581  SQL injection vulnerability in NewsController.php in the News module 5.3.2 and earlier for TYPO3 allows unauthenticated users to execute arbitrary SQL commands via vectors involving overwriteDemand for order and OrderByAllowed.    7.5  High  2017-04-27  2017-04-13  View
84878  CVE-2017-7589  In OpenIDM through 4.0.0 before 4.5.0, the info endpoint may leak sensitive information upon a request by the anonymous user, as demonstrated by responses with a 200 HTTP status code and a JSON object containing IP address strings. This is related to a missing access-control check in bin/defaults/script/info/login.js.    Medium  2017-04-27  2017-04-13  View
84880  CVE-2017-7591  OpenIDM through 4.0.0 and 4.5.0 is vulnerable to reflected cross-site scripting (XSS) attacks within the Admin UI, as demonstrated by the _sortKeys parameter to the authzRoles script under managed/user/.    4.3  Medium  2017-04-27  2017-04-13  View
84881  CVE-2017-7592  The putagreytile function in tif_getimage.c in LibTIFF 4.0.7 has a left-shift undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image.    6.8  Medium  2017-04-27  2017-04-13  View

Page 15838 of 17672, showing 5 records out of 88360 total, starting on record 79186, ending on 79190

Actions