NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
85345  CVE-2016-7051  XmlMapper in the Jackson XML dataformat component (aka jackson-dataformat-xml) before 2.7.8 and 2.8.x before 2.8.4 allows remote attackers to conduct server-side request forgery (SSRF) attacks via vectors related to a DTD.    Medium  2017-05-27  2017-05-25  View
85601  CVE-2017-8794  An issue was discovered on Accellion FTA devices before FTA_9_12_180. Because a regular expression (intended to match local https URLs) lacks an initial ^ character, courier/web/1000@/wmProgressval.html allows SSRF attacks with a file:///etc/passwd#https:// URL pattern.    6.4  Medium  2017-05-27  2017-05-17  View
86113  CVE-2017-8879  Dolibarr ERP/CRM 4.0.4 allows password changes without supplying the current password, which makes it easier for physically proximate attackers to obtain access via an unattended workstation.    4.6  Medium  2017-05-27  2017-05-15  View
85602  CVE-2017-8795  An issue was discovered on Accellion FTA devices before FTA_9_12_180. There is XSS in home/seos/courier/smtpg_add.html with the param parameter.    4.3  Medium  2017-05-27  2017-05-17  View
86114  CVE-2017-8890  The inet_csk_clone_lock function in net/ipv4/inet_connection_sock.c in the Linux kernel through 4.10.15 allows attackers to cause a denial of service (double free) or possibly have unspecified other impact by leveraging use of the accept system call.    10  High  2017-05-27  2017-05-24  View

Page 16027 of 17672, showing 5 records out of 88360 total, starting on record 80131, ending on 80135

Actions