NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
86720  CVE-2017-9546  admin.php in BigTree through 4.2.18 allows remote authenticated users to cause a denial of service (inability to save revisions) via XSS sequences in a revision name.    3.5  Low  2017-06-17  2017-06-15  View
86721  CVE-2017-9547  admin.php in BigTree through 4.2.18 has a Cross-site Scripting (XSS) vulnerability, which allows remote authenticated users to inject arbitrary web script or HTML by launching an Edit Page action and entering the Navigation Title or Page Title of a page that is scheduled for future publication (aka a pending page change).    3.5  Low  2017-06-17  2017-06-15  View
86722  CVE-2017-9548  admin.php in BigTree through 4.2.18 has a Cross-site Scripting (XSS) vulnerability, which allows remote authenticated users to inject arbitrary web script or HTML by launching a Home Template Edit Page action and entering the Navigation Title of a page that is scheduled for future publication (aka a pending page change).    3.5  Low  2017-06-17  2017-06-15  View
87097  CVE-2017-9552  A design flaw in authentication in Synology Photo Station 6.0-2528 through 6.7.1-3419 allows local users to obtain credentials via cmdline. Synology Photo Station employs the synophoto_dsm_user program to authenticate username and password by synophoto_dsm_user --auth USERNAME PASSWORD, and local users are able to obtain credentials by sniffing /proc/*/cmdline.    2.1  Low  2017-07-18  2017-07-03  View
87098  CVE-2017-9557  register.ghp in EFS Software Easy Chat Server versions 2.0 to 3.1 allows remote attackers to discover passwords by sending the username parameter in conjunction with an empty password parameter, and reading the HTML source code of the response.    Medium  2017-06-23  2017-06-22  View

Page 17627 of 17672, showing 5 records out of 88360 total, starting on record 88131, ending on 88135

Actions