NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
86204  CVE-2017-9080  PlaySMS 1.4 allows remote code execution because PHP code in the name of an uploaded .php file is executed. sendfromfile.php has a combination of Unrestricted File Upload and Code Injection.    7.5  High  2017-06-03  2017-06-01  View
86205  CVE-2017-9083  poppler 0.54.0, as used in Evince and other products, has a NULL pointer dereference in the JPXStream::readUByte function in JPXStream.cc. For example, the perf_test utility will crash (segmentation fault) when parsing an invalid PDF file.    4.3  Medium  2017-06-03  2017-05-31  View
85694  CVE-2017-0245  The kernel-mode drivers in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1 and Windows Server 2012 Gold allow a local authenticated attacker to execute a specially crafted application to obtain kernel information, aka Win32k Information Disclosure Vulnerability.    1.9  Low  2017-06-03  2017-05-31  View
86209  CVE-2017-9094  The lzw_add_to_dict function in imagew-gif.c in libimageworsener.a in ImageWorsener 1.3.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted image.    4.3  Medium  2017-06-03  2017-06-01  View
86210  CVE-2017-9098  ImageMagick before 7.0.5-2 and GraphicsMagick before 1.3.24 use uninitialized memory in the RLE decoder, allowing an attacker to leak sensitive information from process memory space, as demonstrated by remote attacks against ImageMagick code in a long-running server process that converts image data on behalf of multiple users. This is caused by a missing initialization step in the ReadRLEImage function in coders/rle.c.    Medium  2017-06-03  2017-06-02  View

Page 16112 of 17672, showing 5 records out of 88360 total, starting on record 80556, ending on 80560

Actions