NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
87575 | CVE-2017-1000036 | All versions of Candy Chat are vulnerable to an XSS attack by message senders, permitting remote code execution within the page | 2017-07-18 | 2017-07-17 | View | ||||
87831 | CVE-2017-11329 | GLPI before 9.1.5 allows SQL injection via an ajax/getDropdownValue.php request with an entity_restrict parameter that is not a list of integers. | 2017-07-18 | 2017-07-17 | View | ||||
87576 | CVE-2017-1000037 | RVM automatically loads environment variables from files in $PWD resulting in command execution RVM vulnerable to command injection when automatically loading environment variables from files in $PWD RVM automatically executes hooks located in $PWD resulting in code execution RVM automatically installs gems as specified by files in $PWD resulting in code execution RVM automatically does bundle install on a Gemfile specified by .versions.conf in $PWD resulting in code execution | 2017-07-18 | 2017-07-17 | View | ||||
87832 | CVE-2017-11335 | There is a heap based buffer overflow in tools/tiff2pdf.c of LibTIFF 4.0.8 via a PlanarConfig=Contig image, which causes a more than one hundred bytes out-of-bounds write (related to the ZIPDecode function in tif_zip.c). A crafted input may lead to a remote denial of service attack or an arbitrary code execution attack. | 2017-07-18 | 2017-07-17 | View | ||||
88088 | CVE-2017-7672 | If an application allows enter an URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL. Solution is to upgrade to Apache Struts version 2.5.12. | 2017-07-18 | 2017-07-17 | View |
Page 17567 of 17672, showing 5 records out of 88360 total, starting on record 87831, ending on 87835