NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
84976  CVE-2017-7881  BigTree CMS through 4.2.17 relies on a substring check for CSRF protection, which allows remote attackers to bypass this check by placing the required admin/developer/ URI within a query string in an HTTP Referer header. This was found in core/admin/modules/developer/_header.php and patched in core/inc/bigtree/admin.php on 2017-04-14.    6.8  Medium  2017-04-27  2017-04-21  View
85232  CVE-2013-7450  Pulp before 2.3.0 uses the same the same certificate authority key and certificate for all installations.    Medium  2017-04-27  2017-04-26  View
38128  CVE-2013-2005  X.org libXt 1.1.3 and earlier does not check the return value of the XGetWindowProperty function, which allows X servers to trigger use of an uninitialized pointer and memory corruption via vectors related to the (1) ReqCleanup, (2) HandleSelectionEvents, (3) ReqTimedOut, (4) HandleNormal, and (5) HandleSelectionReplies functions.    6.8  Medium  2017-04-27  2017-04-20  View
84209  CVE-2017-0885  Nextcloud Server before 9.0.55 and 10.0.2 suffers from a error message disclosing existence of file in write-only share. Due to an error in the application logic an adversary with access to a write-only share may enumerate the names of existing files and subfolders by comparing the exception messages.    Medium  2017-04-27  2017-04-10  View
84977  CVE-2017-7882  LibreOffice before 2017-03-14 has an out-of-bounds write related to the HWPFile::TagsRead function in hwpfilter/source/hwpfile.cxx.    7.5  High  2017-04-27  2017-04-21  View

Page 15920 of 17672, showing 5 records out of 88360 total, starting on record 79596, ending on 79600

Actions