NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
85345 | CVE-2016-7051 | XmlMapper in the Jackson XML dataformat component (aka jackson-dataformat-xml) before 2.7.8 and 2.8.x before 2.8.4 allows remote attackers to conduct server-side request forgery (SSRF) attacks via vectors related to a DTD. | 2 | 5 | Medium | 2017-05-27 | 2017-05-25 | View | |
85601 | CVE-2017-8794 | An issue was discovered on Accellion FTA devices before FTA_9_12_180. Because a regular expression (intended to match local https URLs) lacks an initial ^ character, courier/web/1000@/wmProgressval.html allows SSRF attacks with a file:///etc/passwd#https:// URL pattern. | 2 | 6.4 | Medium | 2017-05-27 | 2017-05-17 | View | |
86113 | CVE-2017-8879 | Dolibarr ERP/CRM 4.0.4 allows password changes without supplying the current password, which makes it easier for physically proximate attackers to obtain access via an unattended workstation. | 2 | 4.6 | Medium | 2017-05-27 | 2017-05-15 | View | |
85602 | CVE-2017-8795 | An issue was discovered on Accellion FTA devices before FTA_9_12_180. There is XSS in home/seos/courier/smtpg_add.html with the param parameter. | 2 | 4.3 | Medium | 2017-05-27 | 2017-05-17 | View | |
86114 | CVE-2017-8890 | The inet_csk_clone_lock function in net/ipv4/inet_connection_sock.c in the Linux kernel through 4.10.15 allows attackers to cause a denial of service (double free) or possibly have unspecified other impact by leveraging use of the accept system call. | 2 | 10 | High | 2017-05-27 | 2017-05-24 | View |
Page 16027 of 17672, showing 5 records out of 88360 total, starting on record 80131, ending on 80135