NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
87094  CVE-2017-9502  In curl before 7.54.1 on Windows and DOS, libcurl's default protocol function, which is the logic that allows an application to set which protocol libcurl should attempt to use when given a URL without a scheme part, had a flaw that could lead to it overwriting a heap based memory buffer with seven bytes. If the default protocol is specified to be FILE or a file: URL lacks two slashes, the given URL starts with a drive letter, and libcurl is built for Windows or DOS, then libcurl would copy the path 7 bytes off, so that the end of the given path would write beyond the malloc buffer (7 bytes being the length in bytes of the ascii string file://).    Medium  2017-07-18  2017-07-07  View
87606  CVE-2017-1000069  CSRF in Bitly oauth2_proxy 2.1 during authentication flow          2017-07-18  2017-07-17  View
87862  CVE-2017-11416  Fiyo CMS 2.0.7 has SQL injection in /apps/app_comment/controller/insert.php via the name parameter.          2017-07-18  2017-07-18  View
88118  CVE-2017-8006  In EMC RSA Authentication Manager 8.2 SP1 Patch 1 and earlier, a malicious user logged into the Self-Service Console of RSA Authentication Manager as a target user can use a brute force attack to attempt to identify that user's PIN. The malicious user could potentially reset the compromised PIN to affect victim's ability to obtain access to protected resources.          2017-07-18  2017-07-17  View
66103  CVE-2005-0340  Integer signedness error in Apple File Service (AFP Server) allows remote attackers to cause a denial of service (application crash) via a negative UAM string length in a FPLoginExt packet.    Medium  2017-07-18  2017-07-10  View

Page 16600 of 17672, showing 5 records out of 88360 total, starting on record 82996, ending on 83000

Actions