NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
83231  CVE-2017-5633  Multiple cross-site request forgery (CSRF) vulnerabilities on the D-Link DI-524 Wireless Router with firmware 9.01 allow remote attackers to (1) change the admin password, (2) reboot the device, or (3) possibly have unspecified other impact via crafted requests to CGI programs.    8.5  High  2017-03-18  2017-03-09  View
83232  CVE-2017-5638  The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 mishandles file upload, which allows remote attackers to execute arbitrary commands via a #cmd= string in a crafted Content-Type HTTP header, as exploited in the wild in March 2017.    10  High  2017-07-18  2017-07-17  View
83233  CVE-2017-5643  Apache Camel's Validation Component is vulnerable against SSRF via remote DTDs and XXE.    5.8  Medium  2017-04-27  2017-03-31  View
83234  CVE-2017-5665  The splt_cue_export_to_file function in cue.c in libmp3splt 0.9.2 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted file.    4.3  Medium  2017-03-18  2017-03-02  View
83235  CVE-2017-5666  The free_options function in options_manager.c in mp3splt 2.6.2 allows remote attackers to cause a denial of service (invalid free and crash) via a crafted file.    4.3  Medium  2017-03-18  2017-03-03  View

Page 16647 of 17672, showing 5 records out of 88360 total, starting on record 83231, ending on 83235

Actions