NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
84461  CVE-2017-3434  Vulnerability in the Oracle One-to-One Fulfillment component of Oracle E-Business Suite (subcomponent: Audience workbench). Supported versions that are affected are 12.1.1, 12.1.2 and 12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle One-to-One Fulfillment. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle One-to-One Fulfillment accessible data as well as unauthorized read access to a subset of Oracle One-to-One Fulfillment accessible data. CVSS 3.0 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N).    6.8  Medium  2017-05-07  2017-05-04  View
85509  CVE-2017-8294  libyara/re.c in the regex component in YARA 3.5.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted rule that is mishandled in the yr_re_exec function.    Medium  2017-05-07  2017-05-03  View
85513  CVE-2017-8298  cnvs.io Canvas 3.3.0 has XSS in the title and content fields of a Posts > Add New action, and during creation of new tags and users.    3.5  Low  2017-05-07  2017-05-03  View
85004  CVE-2017-7983  In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), mail sent using the JMail API leaked the used PHPMailer version in the mail headers.    Medium  2017-05-07  2017-05-03  View
85008  CVE-2017-7987  In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate escaping of file and folder names leads to XSS vulnerabilities in the template manager component.    4.3  Medium  2017-05-07  2017-05-03  View

Page 1715 of 17672, showing 5 records out of 88360 total, starting on record 8571, ending on 8575

Actions