NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
85499 | CVE-2017-7981 | Tuleap before 9.7 allows command injection via the PhpWiki 1.3.10 SyntaxHighlighter plugin. This occurs in the Project Wiki component because the proc_open PHP function is used within PhpWiki before 1.5.5 with a syntax value in its first argument, and an authenticated Tuleap user can control this value, even with shell metacharacters, as demonstrated by a '<?plugin SyntaxHighlighter syntax=c;id' line to execute the id command. | 2 | 9 | High | 2017-05-27 | 2017-05-11 | View | |
85511 | CVE-2017-8296 | kedpm 0.5 and 1.0 creates a history file in ~/.kedpm/history that is written in cleartext. All of the commands performed in the password manager are written there. This can lead to the disclosure of the master password if the password command is used with an argument. The names of the password entries created and consulted are also accessible in cleartext. | 2 | 5 | Medium | 2017-05-27 | 2017-05-10 | View | |
85512 | CVE-2017-8297 | A path traversal vulnerability exists in simple-file-manager before 2017-04-26, affecting index.php (the sole Simple PHP File Manager component). | 2 | 7.5 | High | 2017-05-27 | 2017-05-10 | View | |
85514 | CVE-2017-8301 | LibreSSL 2.5.1 to 2.5.3 lacks TLS certificate verification if SSL_get_verify_result is relied upon for a later check of a verification result, in a use case where a user-provided verification callback returns 1, as demonstrated by acceptance of invalid certificates by nginx. | 2 | 2.6 | Low | 2017-05-27 | 2017-05-10 | View | |
85529 | CVE-2017-8346 | In ImageMagick 7.0.5-5, the ReadDCMImage function in dcm.c allows attackers to cause a denial of service (memory leak) via a crafted file. | 2 | 4.3 | Medium | 2017-05-27 | 2017-05-10 | View |
Page 1683 of 17672, showing 5 records out of 88360 total, starting on record 8411, ending on 8415