NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 83454 | CVE-2017-6811 | paintballrefjosh/MaNGOSWebV4 4.0.8 is vulnerable to a reflected XSS in inc/admin/template_files/admin.shop.php (id parameter). | 2 | 4.3 | Medium | 2017-03-18 | 2017-03-17 | View | |
| 83455 | CVE-2017-6812 | paintballrefjosh/MaNGOSWebV4 4.0.8 is vulnerable to a reflected XSS in inc/admin/template_files/admin.vote.php (id parameter). | 2 | 4.3 | Medium | 2017-03-18 | 2017-03-17 | View | |
| 82432 | CVE-2016-8693 | Double free vulnerability in the mem_close function in jas_stream.c in JasPer before 1.900.10 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted BMP image to the imginfo command. | 2 | 6.8 | Medium | 2017-02-28 | 2017-02-22 | View | |
| 82688 | CVE-2016-4675 | An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The issue involves the "libxpc" component. It allows attackers to execute arbitrary code in a privileged context via a crafted app. | 2 | 9.3 | High | 2017-02-28 | 2017-02-21 | View | |
| 81665 | CVE-2017-5595 | A file disclosure and inclusion vulnerability exists in web/views/file.php in ZoneMinder 1.x through v1.30.0 because of unfiltered user-input being passed to readfile(), which allows an authenticated attacker to read local system files (e.g., /etc/passwd) in the context of the web server user (www-data). The attack vector is a .. (dot dot) in the path parameter within a zm/index.php?view=file&path= request. | 2 | 2.1 | Low | 2017-02-28 | 2017-02-16 | View |
Page 2069 of 17672, showing 5 records out of 88360 total, starting on record 10341, ending on 10345