NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
83848  CVE-2017-7251  A Cross-Site Scripting (XSS) was discovered in pi-engine/pi 2.5.0. The vulnerability exists due to insufficient filtration of user-supplied data (preview) passed to the pi-develop/www/script/editor/markitup/preview/markdown.php URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.    4.3  Medium  2017-03-29  2017-03-28  View
83853  CVE-2017-7261  The vmw_surface_define_ioctl function in drivers/gpu/drm/vmwgfx/vmwgfx_surface.c in the Linux kernel through 4.10.5 does not check for a zero value of certain levels data, which allows local users to cause a denial of service (ZERO_SIZE_PTR dereference, and GPF and possibly panic) via a crafted ioctl call for a /dev/dri/renderD* device.    4.9  Medium  2017-03-29  2017-03-28  View
83855  CVE-2017-7263  The bm_readbody_bmp function in bitmap_io.c in Potrace 1.14 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other impact via a crafted BMP image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-8698.    6.8  Medium  2017-03-29  2017-03-28  View
83856  CVE-2017-7264  Use-after-free vulnerability in the fz_subsample_pixmap function in fitz/pixmap.c in Artifex Software, Inc. MuPDF 1.10a allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted document.    6.8  Medium  2017-03-29  2017-03-28  View
83857  CVE-2017-7266  Netflix Security Monkey before 0.8.0 has an Open Redirect. The logout functionality accepted the next parameter which then redirects to any domain irrespective of the Host header.    5.8  Medium  2017-03-29  2017-03-28  View

Page 1894 of 17672, showing 5 records out of 88360 total, starting on record 9466, ending on 9470

Actions