NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
84209  CVE-2017-0885  Nextcloud Server before 9.0.55 and 10.0.2 suffers from a error message disclosing existence of file in write-only share. Due to an error in the application logic an adversary with access to a write-only share may enumerate the names of existing files and subfolders by comparing the exception messages.    Medium  2017-04-27  2017-04-10  View
84210  CVE-2017-0886  Nextcloud Server before 9.0.55 and 10.0.2 suffers from a Denial of Service attack. Due to an error in the application logic an authenticated adversary may trigger an endless recursion in the application leading to a potential Denial of Service.    Medium  2017-04-27  2017-04-10  View
84211  CVE-2017-0887  Nextcloud Server before 9.0.55 and 10.0.2 suffers from a bypass in the quota limitation. Due to not properly sanitizing values provided by the `OC-Total-Length` HTTP header an authenticated adversary may be able to exceed their configured user quota. Thus using more space than allowed by the administrator.    Medium  2017-04-27  2017-04-10  View
84212  CVE-2017-0888  Nextcloud Server before 9.0.55 and 10.0.2 suffers from a Content-Spoofing vulnerability in the files app. The top navigation bar displayed in the files list contained partially user-controllable input leading to a potential misrepresentation of information.    4.3  Medium  2017-04-27  2017-04-10  View
84218  CVE-2017-1001000  The register_routes function in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in the REST API in WordPress 4.7.x before 4.7.2 does not require an integer identifier, which allows remote attackers to modify arbitrary pages via a request for wp-json/wp/v2/posts followed by a numeric value and a non-numeric value, as demonstrated by the wp-json/wp/v2/posts/123?id=123helloworld URI.    Medium  2017-04-27  2017-04-10  View

Page 1851 of 17672, showing 5 records out of 88360 total, starting on record 9251, ending on 9255

Actions