NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
83231 | CVE-2017-5633 | Multiple cross-site request forgery (CSRF) vulnerabilities on the D-Link DI-524 Wireless Router with firmware 9.01 allow remote attackers to (1) change the admin password, (2) reboot the device, or (3) possibly have unspecified other impact via crafted requests to CGI programs. | 2 | 8.5 | High | 2017-03-18 | 2017-03-09 | View | |
83232 | CVE-2017-5638 | The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 mishandles file upload, which allows remote attackers to execute arbitrary commands via a #cmd= string in a crafted Content-Type HTTP header, as exploited in the wild in March 2017. | 2 | 10 | High | 2017-07-18 | 2017-07-17 | View | |
83233 | CVE-2017-5643 | Apache Camel's Validation Component is vulnerable against SSRF via remote DTDs and XXE. | 2 | 5.8 | Medium | 2017-04-27 | 2017-03-31 | View | |
83234 | CVE-2017-5665 | The splt_cue_export_to_file function in cue.c in libmp3splt 0.9.2 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted file. | 2 | 4.3 | Medium | 2017-03-18 | 2017-03-02 | View | |
83235 | CVE-2017-5666 | The free_options function in options_manager.c in mp3splt 2.6.2 allows remote attackers to cause a denial of service (invalid free and crash) via a crafted file. | 2 | 4.3 | Medium | 2017-03-18 | 2017-03-03 | View |
Page 16647 of 17672, showing 5 records out of 88360 total, starting on record 83231, ending on 83235