NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
85499  CVE-2017-7981  Tuleap before 9.7 allows command injection via the PhpWiki 1.3.10 SyntaxHighlighter plugin. This occurs in the Project Wiki component because the proc_open PHP function is used within PhpWiki before 1.5.5 with a syntax value in its first argument, and an authenticated Tuleap user can control this value, even with shell metacharacters, as demonstrated by a '<?plugin SyntaxHighlighter syntax=c;id' line to execute the id command.    High  2017-05-27  2017-05-11  View
85511  CVE-2017-8296  kedpm 0.5 and 1.0 creates a history file in ~/.kedpm/history that is written in cleartext. All of the commands performed in the password manager are written there. This can lead to the disclosure of the master password if the password command is used with an argument. The names of the password entries created and consulted are also accessible in cleartext.    Medium  2017-05-27  2017-05-10  View
85512  CVE-2017-8297  A path traversal vulnerability exists in simple-file-manager before 2017-04-26, affecting index.php (the sole Simple PHP File Manager component).    7.5  High  2017-05-27  2017-05-10  View
85514  CVE-2017-8301  LibreSSL 2.5.1 to 2.5.3 lacks TLS certificate verification if SSL_get_verify_result is relied upon for a later check of a verification result, in a use case where a user-provided verification callback returns 1, as demonstrated by acceptance of invalid certificates by nginx.    2.6  Low  2017-05-27  2017-05-10  View
85529  CVE-2017-8346  In ImageMagick 7.0.5-5, the ReadDCMImage function in dcm.c allows attackers to cause a denial of service (memory leak) via a crafted file.    4.3  Medium  2017-05-27  2017-05-10  View

Page 1683 of 17672, showing 5 records out of 88360 total, starting on record 8411, ending on 8415

Actions