NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
85069 | CVE-2017-8291 | Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a /OutputFile (%pipe% substring in a crafted .eps document that is an input to the gs program, as exploited in the wild in April 2017. | 2 | 6.8 | Medium | 2017-05-27 | 2017-05-26 | View | |
85325 | CVE-2016-4896 | SetsucoCMS all versions does not properly manage sessions, which allows remote attackers to disclose or alter unauthorized information via unspecified vectors. | 2 | 6.4 | Medium | 2017-05-27 | 2017-05-22 | View | |
85581 | CVE-2017-8760 | An issue was discovered on Accellion FTA devices before FTA_9_12_180. There is XSS in courier/1000@/index.html with the auth_params parameter. The device tries to use internal WAF filters to stop specific XSS Vulnerabilities. However, these can be bypassed by using some modifications to the payloads, e.g., URL encoding. | 2 | 4.3 | Medium | 2017-05-27 | 2017-05-17 | View | |
86093 | CVE-2017-8847 | The bufRead::get() function in libzpaq/libzpaq.h in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted archive. | 2 | 4.3 | Medium | 2017-05-27 | 2017-05-16 | View | |
85582 | CVE-2017-8762 | GeniXCMS 1.0.2 has XSS triggered by an authenticated user who submits a page, as demonstrated by a crafted oncut attribute in a B element. | 2 | 3.5 | Low | 2017-05-27 | 2017-05-12 | View |
Page 1620 of 17672, showing 5 records out of 88360 total, starting on record 8096, ending on 8100