NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
87415 | CVE-2017-9848 | SQL injection vulnerability in C_InfoService.asmx in WebServices in Easysite 7.0 could allow remote attackers to execute arbitrary SQL commands via an XML document containing a crafted ArticleIDs element within a GetArticleHitsArray element. | 2 | 7.5 | High | 2017-07-18 | 2017-07-06 | View | |
87414 | CVE-2017-9847 | The bdecode function in bdecode.cpp in libtorrent 1.1.3 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file. | 2 | 4.3 | Medium | 2017-07-18 | 2017-06-29 | View | |
87413 | CVE-2017-9846 | Winmail Server 6.1 allows remote code execution by authenticated users who leverage directory traversal in a netdisk.php move_folder_file call to move a .php file from the FTP folder into a web folder. | 2 | 6.5 | Medium | 2017-07-18 | 2017-06-30 | View | |
87412 | CVE-2017-9841 | Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a <?php substring, as demonstrated by an attack on a site with an exposed /vendor folder, i.e., external access to the /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php URI. | 2 | 7.5 | High | 2017-07-18 | 2017-07-06 | View | |
87411 | CVE-2017-9840 | Dolibarr ERP/CRM 5.0.3 and prior allows low-privilege users to upload files of dangerous types, which can result in arbitrary code execution within the context of the vulnerable application. | 2 | 6.5 | Medium | 2017-07-18 | 2017-06-30 | View |
Page 190 of 17672, showing 5 records out of 88360 total, starting on record 946, ending on 950