NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
86048 | CVE-2017-7888 | Dolibarr ERP/CRM 4.0.4 stores passwords with the MD5 algorithm, which makes brute-force attacks easier. | 2 | 5 | Medium | 2017-05-27 | 2017-05-15 | View | |
84979 | CVE-2017-7889 | The mm subsystem in the Linux kernel through 4.10.10 does not properly enforce the CONFIG_STRICT_DEVMEM protection mechanism, which allows local users to read or write to kernel memory locations in the first megabyte (and bypass slab-allocation access restrictions) via an application that opens the /dev/mem file, related to arch/x86/mm/init.c and drivers/char/mem.c. | 2 | 7.2 | High | 2017-04-27 | 2017-04-21 | View | |
84980 | CVE-2017-7891 | sourcebans-pp (SourceBans++) 1.5.4.7 has XSS in admin.comms.php via the rebanid parameter. | 2 | 4.3 | Medium | 2017-04-27 | 2017-04-25 | View | |
84981 | CVE-2017-7892 | Sandstorm Cap'n Proto before 0.5.3.1 allows remote crashes related to a compiler optimization. A remote attacker can trigger a segfault in a 32-bit libcapnp application because Cap'n Proto relies on pointer arithmetic calculations that overflow. An example compiler with optimization that elides a bounds check in such calculations is Apple LLVM version 8.1.0 (clang-802.0.41). The attack vector is a crafted far pointer within a message. | 2 | 5 | Medium | 2017-04-27 | 2017-04-25 | View | |
88103 | CVE-2017-7894 | WinDjView 2.1 might allow user-assisted attackers to execute code via a crafted .djvu file, because of a User Mode Write AV near NULL in WinDjView.exe. One threat model is a victim who obtains an untrusted .djvu file from a remote location and issues several zoom in (e.g., Ctrl + Plus) commands. | 2 | 6.8 | Medium | 2017-07-18 | 2017-07-14 | View |
Page 17453 of 17672, showing 5 records out of 88360 total, starting on record 87261, ending on 87265