NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
86204  CVE-2017-9080  PlaySMS 1.4 allows remote code execution because PHP code in the name of an uploaded .php file is executed. sendfromfile.php has a combination of Unrestricted File Upload and Code Injection.    7.5  High  2017-06-03  2017-06-01  View
86205  CVE-2017-9083  poppler 0.54.0, as used in Evince and other products, has a NULL pointer dereference in the JPXStream::readUByte function in JPXStream.cc. For example, the perf_test utility will crash (segmentation fault) when parsing an invalid PDF file.    4.3  Medium  2017-06-03  2017-05-31  View
86206  CVE-2017-9090  reg.php in Allen Disk 1.6 doesn't check if isset($_SESSION['captcha']['code'])==1, which makes it possible to bypass the CAPTCHA via an empty $_POST['captcha'].    Medium  2017-05-27  2017-05-24  View
86207  CVE-2017-9091  /admin/loginc.php in Allen Disk 1.6 doesn't check if isset($_SESSION['captcha']['code']) == 1, which leads to CAPTCHA bypass by emptying $_POST['captcha'].    Medium  2017-05-27  2017-05-24  View
86208  CVE-2017-9093  The my_skip_input_data_fn function in imagew-jpeg.c in libimageworsener.a in ImageWorsener 1.3.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted image.    4.3  Medium  2017-05-27  2017-05-24  View

Page 17570 of 17672, showing 5 records out of 88360 total, starting on record 87846, ending on 87850

Actions