NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
86670 | CVE-2017-9332 | The smarty_self function in modules/module_smarty.php in PivotX 2.3.11 mishandles the URI, allowing XSS via vectors involving quotes in the self Smarty tag. | 2 | 4.3 | Medium | 2017-06-17 | 2017-06-14 | View | |
86697 | CVE-2017-9465 | The yr_arena_write_data function in YARA 3.6.1 allows remote attackers to cause a denial of service (buffer over-read and application crash) or obtain sensitive information from process memory via a crafted file that is mishandled in the yr_re_fast_exec function in libyara/re.c and the _yr_scan_match_callback function in libyara/scan.c. | 2 | 5.8 | Medium | 2017-06-17 | 2017-06-14 | View | |
86708 | CVE-2017-9516 | Craft CMS before 2.6.2982 allows for a potential XSS attack vector by uploading a malicious SVG file. | 2 | 3.5 | Low | 2017-06-17 | 2017-06-14 | View | |
86713 | CVE-2017-9523 | The Sophos Web Appliance before 4.3.2 has XSS in the FTP redirect page, aka NSWA-1342. | 2 | 4.3 | Medium | 2017-06-17 | 2017-06-14 | View | |
86724 | CVE-2014-3498 | The user module in ansible before 1.6.6 allows remote authenticated users to execute arbitrary commands. | 2 | 6.5 | Medium | 2017-06-18 | 2017-06-14 | View |
Page 16201 of 17672, showing 5 records out of 88360 total, starting on record 81001, ending on 81005