NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
86508 | CVE-2017-9303 | Laravel 5.4.x before 5.4.22 does not properly constrain the host portion of a password-reset URL, which makes it easier for remote attackers to conduct phishing attacks by specifying an attacker-controlled host. | 2 | 5.8 | Medium | 2017-06-12 | 2017-06-08 | View | |
86510 | CVE-2017-9305 | lib/core/TikiFilter/PreventXss.php in Tiki Wiki CMS Groupware 16.2 allows remote attackers to bypass the XSS filter via padded zero characters, as demonstrated by an attack on tiki-batch_send_newsletter.php. | 2 | 4.3 | Medium | 2017-06-12 | 2017-06-08 | View | |
85743 | CVE-2017-0373 | The gen_class_pod implementation in lib/Config/Model/Utils/GenClassPod.pm in Config-Model (aka libconfig-model-perl) before 2.102 has a dangerous use lib line, which allows remote attackers to have an unspecified impact via a crafted Debian package file. | 2 | 6.8 | Medium | 2017-06-12 | 2017-06-08 | View | |
85744 | CVE-2017-0374 | lib/Config/Model.pm in Config-Model (aka libconfig-model-perl) before 2.102 allows local users to gain privileges via a crafted model in the current working directory, related to use of . with the INC array. | 2 | 4.6 | Medium | 2017-06-12 | 2017-06-08 | View | |
81916 | CVE-2016-8941 | IBM Tivoli Storage Productivity Center is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. | 2 | 6.8 | Medium | 2017-06-12 | 2017-06-08 | View |
Page 16166 of 17672, showing 5 records out of 88360 total, starting on record 80826, ending on 80830