NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
85937  CVE-2017-5870  Multiple cross-site scripting (XSS) vulnerabilities in ViMbAdmin 3.0.15 allow remote attackers to inject arbitrary web script or HTML via the (1) domain or (2) transport parameter to domain/add; the (3) name parameter to mailbox/add/did/<domain id>; the (4) goto parameter to alias/add/did/<domain id>; or the (5) captchatext parameter to auth/lost-password.    3.5  Low  2017-06-03  2017-06-01  View
86193  CVE-2017-9069  In MODX Revolution before 2.5.7, a user with file upload permissions is able to execute arbitrary code by uploading a file with the name .htaccess.    6.5  Medium  2017-06-03  2017-05-30  View
86194  CVE-2017-9070  In MODX Revolution before 2.5.7, a user with resource edit permissions can inject an XSS payload into the title of any post via the pagetitle parameter to connectors/index.php.    3.5  Low  2017-06-03  2017-05-30  View
86195  CVE-2017-9071  In MODX Revolution before 2.5.7, an attacker might be able to trigger XSS by injecting a payload into the HTTP Host header of a request. This is exploitable only in conjunction with other issues such as Cache Poisoning.    2.6  Low  2017-06-03  2017-05-30  View
86198  CVE-2017-9074  The IPv6 fragmentation implementation in the Linux kernel through 4.11.1 does not consider that the nexthdr field may be associated with an invalid option, which allows local users to cause a denial of service (out-of-bounds read and BUG) or possibly have unspecified other impact via crafted socket and send system calls.    7.2  High  2017-06-03  2017-06-01  View

Page 16110 of 17672, showing 5 records out of 88360 total, starting on record 80546, ending on 80550

Actions