NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
84943  CVE-2017-7725  concrete5 8.1.0 places incorrect trust in the HTTP Host header during caching, if the administrator did not define a canonical URL on installation of concrete5 using the Advanced Options settings. Remote attackers can make a GET request with any domain name in the Host header; this is stored and allows for arbitrary domains to be set for certain links displayed to subsequent visitors, potentially an XSS vector.    4.3  Medium  2017-04-27  2017-04-20  View
85199  CVE-2016-7521  Heap-based buffer overflow in coders/psd.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PSD file.    4.3  Medium  2017-04-27  2017-04-25  View
85200  CVE-2016-7522  The ReadPSDImage function in MagickCore/locale.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PSD file.    4.3  Medium  2017-04-27  2017-04-25  View
84689  CVE-2017-5642  During installation of Ambari 2.4.0 through 2.4.2, Ambari Server artifacts are not created with proper ACLs.    7.5  High  2017-04-27  2017-04-10  View
85201  CVE-2016-7525  Heap-based buffer overflow in coders/psd.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PSD file.    4.3  Medium  2017-04-27  2017-04-25  View

Page 15902 of 17672, showing 5 records out of 88360 total, starting on record 79506, ending on 79510

Actions