NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
85500 | CVE-2017-7995 | Xen PV guest before Xen 4.3 checked access permissions to MMIO ranges only after accessing them, allowing host PCI device space memory reads, leading to information disclosure. This is an error in the get_user function. NOTE: the upstream Xen Project considers versions before 4.5.x to be EOL. | 2 | 1.7 | Low | 2017-05-27 | 2017-05-15 | View | |
85014 | CVE-2017-7994 | The function TextExtractor::ExtractText in TextExtractor.cpp:77 in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted PDF document. | 2 | 4.3 | Medium | 2017-04-27 | 2017-04-26 | View | |
85013 | CVE-2017-7992 | Heartland Payment Systems Payment Gateway PHP SDK hps/heartland-php v2.8.17 is vulnerable to a reflected XSS in examples/consumer-authentication/cruise.php via the URI, as demonstrated by the cavv parameter. | 2 | 4.3 | Medium | 2017-05-07 | 2017-04-27 | View | |
85012 | CVE-2017-7991 | Exponent CMS 2.4.1 and earlier has SQL injection via a base64 serialized API key (apikey parameter) in the api function of framework/modules/eaas/controllers/eaasController.php. | 2 | 7.5 | High | 2017-05-07 | 2017-04-27 | View | |
85011 | CVE-2017-7990 | The Reporting Module 1.12.0 for OpenMRS allows CSRF attacks with resultant XSS, in which administrative authentication is hijacked to insert JavaScript into a name field in webapp/reports/manageReports.jsp. | 2 | 6.8 | Medium | 2017-04-27 | 2017-04-26 | View |
Page 206 of 17672, showing 5 records out of 88360 total, starting on record 1026, ending on 1030