NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
86206 | CVE-2017-9090 | reg.php in Allen Disk 1.6 doesn't check if isset($_SESSION['captcha']['code'])==1, which makes it possible to bypass the CAPTCHA via an empty $_POST['captcha']. | 2 | 5 | Medium | 2017-05-27 | 2017-05-24 | View | |
85439 | CVE-2017-5236 | Editions of Rapid7 AppSpider Pro installers prior to version 6.14.060 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL located in the current working directory of the installer. | 2 | 6.8 | Medium | 2017-05-27 | 2017-05-15 | View | |
85951 | CVE-2017-6195 | Ipswitch MOVEit Transfer (formerly DMZ) allows pre-authentication blind SQL injection. The fixed versions are MOVEit Transfer 2017 9.0.0.201, MOVEit DMZ 8.3.0.30, and MOVEit DMZ 8.2.0.20. | 2 | 7.5 | High | 2017-05-27 | 2017-05-26 | View | |
86207 | CVE-2017-9091 | /admin/loginc.php in Allen Disk 1.6 doesn't check if isset($_SESSION['captcha']['code']) == 1, which leads to CAPTCHA bypass by emptying $_POST['captcha']. | 2 | 5 | Medium | 2017-05-27 | 2017-05-24 | View | |
85440 | CVE-2017-5240 | Editions of Rapid7 AppSpider Pro prior to version 6.14.060 contain a heap-based buffer overflow in the FLAnalyzer.exe component. A malicious or malformed Flash source file can cause a denial of service condition when parsed by this component, causing the application to crash. | 2 | 5 | Medium | 2017-05-27 | 2017-05-15 | View |
Page 1665 of 17672, showing 5 records out of 88360 total, starting on record 8321, ending on 8325