NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
84976 | CVE-2017-7881 | BigTree CMS through 4.2.17 relies on a substring check for CSRF protection, which allows remote attackers to bypass this check by placing the required admin/developer/ URI within a query string in an HTTP Referer header. This was found in core/admin/modules/developer/_header.php and patched in core/inc/bigtree/admin.php on 2017-04-14. | 2 | 6.8 | Medium | 2017-04-27 | 2017-04-21 | View | |
85232 | CVE-2013-7450 | Pulp before 2.3.0 uses the same the same certificate authority key and certificate for all installations. | 2 | 5 | Medium | 2017-04-27 | 2017-04-26 | View | |
38128 | CVE-2013-2005 | X.org libXt 1.1.3 and earlier does not check the return value of the XGetWindowProperty function, which allows X servers to trigger use of an uninitialized pointer and memory corruption via vectors related to the (1) ReqCleanup, (2) HandleSelectionEvents, (3) ReqTimedOut, (4) HandleNormal, and (5) HandleSelectionReplies functions. | 2 | 6.8 | Medium | 2017-04-27 | 2017-04-20 | View | |
84209 | CVE-2017-0885 | Nextcloud Server before 9.0.55 and 10.0.2 suffers from a error message disclosing existence of file in write-only share. Due to an error in the application logic an adversary with access to a write-only share may enumerate the names of existing files and subfolders by comparing the exception messages. | 2 | 4 | Medium | 2017-04-27 | 2017-04-10 | View | |
84977 | CVE-2017-7882 | LibreOffice before 2017-03-14 has an out-of-bounds write related to the HWPFile::TagsRead function in hwpfilter/source/hwpfile.cxx. | 2 | 7.5 | High | 2017-04-27 | 2017-04-21 | View |
Page 15920 of 17672, showing 5 records out of 88360 total, starting on record 79596, ending on 79600