NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
87795 | CVE-2017-11143 | In PHP before 5.6.31, an invalid free in the WDDX deserialization of boolean parameters could be used by attackers able to inject XML for deserialization to crash the PHP interpreter, related to an invalid free for an empty boolean element in ext/wddx/wddx.c. | 2 | 5 | Medium | 2017-07-18 | 2017-07-17 | View | |
88307 | CVE-2016-4996 | discovery-debug in Foreman before 6.2 when the ssh service has been enabled on discovered nodes displays the root password in plaintext in the system journal when used to log in, which allows local users with access to the system journal to obtain the root password by reading the system journal, or by clicking Logs on the console. | 2017-07-18 | 2017-07-17 | View | ||||
88308 | CVE-2016-6019 | IBM Emptoris Strategic Supply Management Platform 10.0.0.x through 10.1.1.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 116739. | 2017-07-18 | 2017-07-17 | View | ||||
25588 | CVE-2015-4038 | The WP Membership plugin 1.2.3 for WordPress allows remote authenticated users to gain administrator privileges via an iv_membership_update_user_settings action to wp-admin/admin-ajax.php. | 2 | 6.5 | Medium | 2017-07-18 | 2017-07-17 | View | |
87541 | CVE-2017-1000001 | FedMsg 0.18.1 and older is vulnerable to a message validation flaw resulting in message validation not being enabled if configured to be on. | 2017-07-18 | 2017-07-17 | View |
Page 17660 of 17672, showing 5 records out of 88360 total, starting on record 88296, ending on 88300