NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
87339  CVE-2017-9781  A cross site scripting (XSS) vulnerability exists in Check_MK versions 1.4.0x prior to 1.4.0p6, allowing an unauthenticated remote attacker to inject arbitrary HTML or JavaScript via the _username parameter when attempting authentication to webapi.py, which is returned unencoded with content type text/html.    4.3  Medium  2017-07-18  2017-06-29  View
87380  CVE-2017-7416  ntopng before 3.0 allows XSS because GET and POST parameters are improperly validated.    4.3  Medium  2017-07-18  2017-06-29  View
87381  CVE-2017-7458  The NetworkInterface::getHost function in NetworkInterface.cpp in ntopng before 3.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty field that should have contained a hostname or IP address.    Medium  2017-07-18  2017-06-29  View
87382  CVE-2017-7459  ntopng before 3.0 allows HTTP Response Splitting.    Medium  2017-07-18  2017-06-29  View
87404  CVE-2017-9615  Password exposure in Cognito Software Moneyworks 8.0.3 and earlier allows attackers to gain administrator access to all data, because verbose logging writes the administrator password to a world-readable file.    Medium  2017-07-18  2017-06-29  View

Page 16298 of 17672, showing 5 records out of 88360 total, starting on record 81486, ending on 81490

Actions