NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
86048 | CVE-2017-7888 | Dolibarr ERP/CRM 4.0.4 stores passwords with the MD5 algorithm, which makes brute-force attacks easier. | 2 | 5 | Medium | 2017-05-27 | 2017-05-15 | View | |
85803 | CVE-2017-1103 | IBM Team Concert (RTC) is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM X-Force ID: 120665. | 2 | 7.5 | High | 2017-05-27 | 2017-05-15 | View | |
85574 | CVE-2017-8419 | LAME through 3.99.5 relies on the signed integer data type for values in a WAV or AIFF header, which allows remote attackers to cause a denial of service (stack-based buffer overflow or heap-based buffer overflow) or possibly have unspecified other impact via a crafted file, as demonstrated by mishandling of num_channels. | 2 | 6.8 | Medium | 2017-05-27 | 2017-05-15 | View | |
86088 | CVE-2017-8842 | The bufRead::get() function in libzpaq/libzpaq.h in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted archive. | 2 | 4.3 | Medium | 2017-05-27 | 2017-05-15 | View | |
85583 | CVE-2017-8763 | Cross-site scripting (XSS) vulnerability in modules/Base/Box/check_for_new_version.php in EPESI in Telaxus/EPESI 1.8.2 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted URI that lacks the cid parameter. | 2 | 4.3 | Medium | 2017-05-27 | 2017-05-15 | View |
Page 16004 of 17672, showing 5 records out of 88360 total, starting on record 80016, ending on 80020