NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
87094 | CVE-2017-9502 | In curl before 7.54.1 on Windows and DOS, libcurl's default protocol function, which is the logic that allows an application to set which protocol libcurl should attempt to use when given a URL without a scheme part, had a flaw that could lead to it overwriting a heap based memory buffer with seven bytes. If the default protocol is specified to be FILE or a file: URL lacks two slashes, the given URL starts with a drive letter, and libcurl is built for Windows or DOS, then libcurl would copy the path 7 bytes off, so that the end of the given path would write beyond the malloc buffer (7 bytes being the length in bytes of the ascii string file://). | 2 | 5 | Medium | 2017-07-18 | 2017-07-07 | View | |
87606 | CVE-2017-1000069 | CSRF in Bitly oauth2_proxy 2.1 during authentication flow | 2017-07-18 | 2017-07-17 | View | ||||
87862 | CVE-2017-11416 | Fiyo CMS 2.0.7 has SQL injection in /apps/app_comment/controller/insert.php via the name parameter. | 2017-07-18 | 2017-07-18 | View | ||||
88118 | CVE-2017-8006 | In EMC RSA Authentication Manager 8.2 SP1 Patch 1 and earlier, a malicious user logged into the Self-Service Console of RSA Authentication Manager as a target user can use a brute force attack to attempt to identify that user's PIN. The malicious user could potentially reset the compromised PIN to affect victim's ability to obtain access to protected resources. | 2017-07-18 | 2017-07-17 | View | ||||
66103 | CVE-2005-0340 | Integer signedness error in Apple File Service (AFP Server) allows remote attackers to cause a denial of service (application crash) via a negative UAM string length in a FPLoginExt packet. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View |
Page 16600 of 17672, showing 5 records out of 88360 total, starting on record 82996, ending on 83000