NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
85512  CVE-2017-8297  A path traversal vulnerability exists in simple-file-manager before 2017-04-26, affecting index.php (the sole Simple PHP File Manager component).    7.5  High  2017-05-27  2017-05-10  View
85511  CVE-2017-8296  kedpm 0.5 and 1.0 creates a history file in ~/.kedpm/history that is written in cleartext. All of the commands performed in the password manager are written there. This can lead to the disclosure of the master password if the password command is used with an argument. The names of the password entries created and consulted are also accessible in cleartext.    Medium  2017-05-27  2017-05-10  View
85510  CVE-2017-8295  WordPress through 4.7.4 relies on the Host HTTP header for a password-reset e-mail message, which makes it easier for remote attackers to reset arbitrary passwords by making a crafted wp-login.php?action=lostpassword request and then arranging for this message to bounce or be resent, leading to transmission of the reset key to a mailbox on an attacker-controlled SMTP server. This is related to problematic use of the SERVER_NAME variable in wp-includes/pluggable.php in conjunction with the PHP mail function. Exploitation is not achievable in all cases because it requires at least one of the following: (1) the attacker can prevent the victim from receiving any e-mail messages for an extended period of time (such as 5 days), (2) the victim's e-mail system sends an autoresponse containing the original message, or (3) the victim manually composes a reply containing the original message.    4.3  Medium  2017-07-18  2017-07-17  View
85509  CVE-2017-8294  libyara/re.c in the regex component in YARA 3.5.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted rule that is mishandled in the yr_re_exec function.    Medium  2017-05-07  2017-05-03  View
85069  CVE-2017-8291  Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a /OutputFile (%pipe% substring in a crafted .eps document that is an input to the gs program, as exploited in the wild in April 2017.    6.8  Medium  2017-05-27  2017-05-26  View

Page 187 of 17672, showing 5 records out of 88360 total, starting on record 931, ending on 935

Actions