NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
83857 | CVE-2017-7266 | Netflix Security Monkey before 0.8.0 has an Open Redirect. The logout functionality accepted the next parameter which then redirects to any domain irrespective of the Host header. | 2 | 5.8 | Medium | 2017-03-29 | 2017-03-28 | View | |
83858 | CVE-2017-7269 | Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server 2003 R2 allows remote attackers to execute arbitrary code via a long header beginning with If: <http:// in a PROPFIND request, as exploited in the wild in July or August 2016. | 2 | 10 | High | 2017-07-18 | 2017-07-11 | View | |
83859 | CVE-2017-7271 | Reflected Cross-site scripting (XSS) vulnerability in Yii Framework before 2.0.11, when development mode is used, allows remote attackers to inject arbitrary web script or HTML via crafted request data that is mishandled on the debug-mode exception screen. | 2 | 4.3 | Medium | 2017-05-27 | 2017-05-07 | View | |
83860 | CVE-2017-7272 | PHP through 7.1.3 enables potential SSRF in applications that accept an fsockopen hostname argument with an expectation that the port number is constrained. Because a :port syntax is recognized, fsockopen will use the port number that is specified in the hostname argument, instead of the port number in the second argument of the function. | 2 | 5.8 | Medium | 2017-07-18 | 2017-07-11 | View | |
83861 | CVE-2017-7273 | The cp_report_fixup function in drivers/hid/hid-cypress.c in the Linux kernel 4.x before 4.9.4 allows physically proximate attackers to cause a denial of service (integer underflow) or possibly have unspecified other impact via a crafted HID report. | 2 | 4.6 | Medium | 2017-04-27 | 2017-04-03 | View |
Page 17386 of 17672, showing 5 records out of 88360 total, starting on record 86926, ending on 86930