NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
86093 | CVE-2017-8847 | The bufRead::get() function in libzpaq/libzpaq.h in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted archive. | 2 | 4.3 | Medium | 2017-05-27 | 2017-05-16 | View | |
85582 | CVE-2017-8762 | GeniXCMS 1.0.2 has XSS triggered by an authenticated user who submits a page, as demonstrated by a crafted oncut attribute in a B element. | 2 | 3.5 | Low | 2017-05-27 | 2017-05-12 | View | |
86094 | CVE-2017-8848 | Allen Disk 1.6 has CSRF in setpass.php with an impact of changing a password. | 2 | 4.3 | Medium | 2017-05-27 | 2017-05-16 | View | |
85583 | CVE-2017-8763 | Cross-site scripting (XSS) vulnerability in modules/Base/Box/check_for_new_version.php in EPESI in Telaxus/EPESI 1.8.2 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted URI that lacks the cid parameter. | 2 | 4.3 | Medium | 2017-05-27 | 2017-05-15 | View | |
45135 | CVE-2012-3546 | org/apache/catalina/realm/RealmBase.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.30, when FORM authentication is used, allows remote attackers to bypass security-constraint checks by leveraging a previous setUserPrincipal call and then placing /j_security_check at the end of a URI. | 2 | 4.3 | Medium | 2017-05-27 | 2017-05-22 | View |
Page 16019 of 17672, showing 5 records out of 88360 total, starting on record 80091, ending on 80095