NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
88201  CVE-2017-9248  Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Telerik.Web.UI.DialogParametersEncryptionKey or the MachineKey, which makes it easier for remote attackers to defeat cryptographic protection mechanisms, leading to a MachineKey leak, arbitrary file uploads or downloads, XSS, or ASP.NET ViewState compromise.    7.5  High  2017-07-18  2017-07-17  View
88202  CVE-2017-9313  Multiple Cross-site scripting (XSS) vulnerabilities in Webmin before 1.850 allow remote attackers to inject arbitrary web script or HTML via the sec parameter to view_man.cgi, the referers parameter to change_referers.cgi, or the name parameter to save_user.cgi. NOTE: these issues were not fixed in 1.840.    4.3  Medium  2017-07-18  2017-07-10  View
88203  CVE-2017-9338  Inadequate escaping lead to XSS vulnerability in the search module in ownCloud Server before 8.2.12, 9.0.x before 9.0.10, 9.1.x before 9.1.6, and 10.0.x before 10.0.2. To be exploitable a user has to write or paste malicious content into the search dialogue.          2017-07-18  2017-07-17  View
88204  CVE-2017-9339  A logical error in ownCloud Server before 10.0.2 caused disclosure of valid share tokens for public calendars. Thus granting an attacker potentially access to publicly shared calendars without knowing the share token.          2017-07-18  2017-07-17  View
88205  CVE-2017-9340  An attacker is logged in as a normal user and can somehow make admin to delete shared folders in ownCloud Server before 10.0.2.          2017-07-18  2017-07-17  View

Page 17641 of 17672, showing 5 records out of 88360 total, starting on record 88201, ending on 88205

Actions