NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
87751 | CVE-2017-10974 | Yaws 1.91 allows Unauthenticated Remote File Disclosure via HTTP Directory Traversal with /%5C../ to port 8080. NOTE: this CVE is only about use of an initial /%5C sequence to defeat traversal protection mechanisms; the initial /%5C sequence was apparently not discussed in earlier research on this product. | 2 | 5 | Medium | 2017-07-18 | 2017-07-14 | View | |
87752 | CVE-2017-10975 | Cross-site scripting (XSS) vulnerability in Lutim before 0.8 might allow remote attackers to inject arbitrary web script or HTML via a crafted filename that is mishandled in an upload notification and in the myfiles component, if the attacker can convince the victim to proceed with an upload despite the appearance of an XSS payload in the filename. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-17 | View | |
87753 | CVE-2017-10976 | When SWFTools 0.9.2 processes a crafted file in ttftool, it can lead to a heap-based buffer over-read in the readBlock() function in lib/ttf.c. | 2 | 5 | Medium | 2017-07-18 | 2017-07-17 | View | |
87754 | CVE-2017-10978 | An FR-GV-201 issue in FreeRADIUS 2.x before 2.2.10 and 3.x before 3.0.15 allows Read / write overflow in make_secret() and a denial of service. | 2017-07-18 | 2017-07-17 | View | ||||
87755 | CVE-2017-10979 | An FR-GV-202 issue in FreeRADIUS 2.x before 2.2.10 allows Write overflow in rad_coalesce() - this allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code. | 2017-07-18 | 2017-07-17 | View |
Page 17551 of 17672, showing 5 records out of 88360 total, starting on record 87751, ending on 87755