NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
87410  CVE-2017-9837  The ws_session_logout function in Piwigo 2.9.1 and earlier does not properly delete user login cookies, which allows remote attackers to gain access via cookie reuse.    7.5  High  2017-06-28  2017-06-27  View
87411  CVE-2017-9840  Dolibarr ERP/CRM 5.0.3 and prior allows low-privilege users to upload files of dangerous types, which can result in arbitrary code execution within the context of the vulnerable application.    6.5  Medium  2017-07-18  2017-06-30  View
87412  CVE-2017-9841  Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a <?php substring, as demonstrated by an attack on a site with an exposed /vendor folder, i.e., external access to the /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php URI.    7.5  High  2017-07-18  2017-07-06  View
88232  CVE-2017-9843  SAP NetWeaver AS ABAP 7.40 allows remote authenticated users with certain privileges to cause a denial of service (process crash) via vectors involving disp+work.exe, aka SAP Security Note 2406841.          2017-07-18  2017-07-12  View
88233  CVE-2017-9844  SAP NetWeaver 7400.12.21.30308 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted serialized Java object in a request to metadatauploader, aka SAP Security Note 2399804.          2017-07-18  2017-07-12  View

Page 17653 of 17672, showing 5 records out of 88360 total, starting on record 88261, ending on 88265

Actions