NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
87797 | CVE-2017-11145 | In PHP before 5.6.31, 7.x before 7.0.21, and 7.1.x before 7.1.7, lack of a bounds check in the date extension's timelib_meridian parsing code could be used by attackers able to supply date strings to leak information from the interpreter, related to an ext/date/lib/parse_date.c out-of-bounds read affecting the php_parse_date function. | 2 | 5 | Medium | 2017-07-18 | 2017-07-17 | View | |
88053 | CVE-2017-6728 | A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitrary code at the root privilege level on an affected system, because of Incorrect Permissions. More Information: CSCvb99389. Known Affected Releases: 6.2.1.BASE. Known Fixed Releases: 6.3.1.15i.BASE 6.2.3.1i.BASE 6.2.2.15i.BASE 6.1.4.10i.BASE. | 2 | 6.9 | Medium | 2017-07-18 | 2017-07-16 | View | |
88309 | CVE-2016-6114 | IBM Emptoris Sourcing 9.5.x through 10.1.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 118352. | 2017-07-18 | 2017-07-17 | View | ||||
40181 | CVE-2013-4598 | The Groups, Communities and Co (GCC) module 7.x-1.x before 7.x-1.1 for Drupal does not properly check permission, which allows remote attackers to access the configuration pages via unspecified vectors. | 2 | 5 | Medium | 2017-07-18 | 2017-07-11 | View | |
66038 | CVE-2005-0275 | TFTP in 3Com 3CDaemon 2.0 revision 10 allows remote attackers to cause a denial of service (application crash) via a GET request containing an MS-DOS device name. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View |
Page 17617 of 17672, showing 5 records out of 88360 total, starting on record 88081, ending on 88085