NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
84943 | CVE-2017-7725 | concrete5 8.1.0 places incorrect trust in the HTTP Host header during caching, if the administrator did not define a canonical URL on installation of concrete5 using the Advanced Options settings. Remote attackers can make a GET request with any domain name in the Host header; this is stored and allows for arbitrary domains to be set for certain links displayed to subsequent visitors, potentially an XSS vector. | 2 | 4.3 | Medium | 2017-04-27 | 2017-04-20 | View | |
85199 | CVE-2016-7521 | Heap-based buffer overflow in coders/psd.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PSD file. | 2 | 4.3 | Medium | 2017-04-27 | 2017-04-25 | View | |
85200 | CVE-2016-7522 | The ReadPSDImage function in MagickCore/locale.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PSD file. | 2 | 4.3 | Medium | 2017-04-27 | 2017-04-25 | View | |
84689 | CVE-2017-5642 | During installation of Ambari 2.4.0 through 2.4.2, Ambari Server artifacts are not created with proper ACLs. | 2 | 7.5 | High | 2017-04-27 | 2017-04-10 | View | |
85201 | CVE-2016-7525 | Heap-based buffer overflow in coders/psd.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PSD file. | 2 | 4.3 | Medium | 2017-04-27 | 2017-04-25 | View |
Page 15902 of 17672, showing 5 records out of 88360 total, starting on record 79506, ending on 79510