NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
83439 | CVE-2017-6589 | EpicEditor through 0.2.3 has Cross-Site Scripting because of an insecure default marked.js configuration. An example attack vector is a crafted IMG element in an HTML document. | 2 | 4.3 | Medium | 2017-03-18 | 2017-03-10 | View | |
84207 | CVE-2017-0883 | Nextcloud Server before 9.0.55 and 10.0.2 suffers from a permission increase on re-sharing via OCS API issue. A permission related issue within the OCS sharing API allowed an authenticated adversary to reshare shared files with an increasing permission set. This may allow an attacker to edit files in a share despite having only a 'read' permission set. Note that this only affects folders and files that the adversary has at least read-only permissions for. | 2 | 5.5 | Medium | 2017-04-27 | 2017-04-10 | View | |
84463 | CVE-2017-3450 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Memcached). Supported versions that are affected are 5.6.35 and earlier and 5.7.17 and earlier. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
84719 | CVE-2017-6033 | A DLL Hijacking issue was discovered in Schneider Electric Interactive Graphical SCADA System (IGSS) Software, Version 12 and previous versions. The software will execute a malicious file if it is named the same as a legitimate file and placed in a location that is earlier in the search path. | 2 | 6.8 | Medium | 2017-04-27 | 2017-04-13 | View | |
84975 | CVE-2017-7879 | SQL Injection vulnerability in flatCore version 1.4.6 allows an attacker to read the content database. | 2 | 5 | Medium | 2017-04-27 | 2017-04-21 | View |
Page 17319 of 17672, showing 5 records out of 88360 total, starting on record 86591, ending on 86595