NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
85005 | CVE-2017-7984 | In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering leads to XSS in the template manager component. | 2 | 4.3 | Medium | 2017-05-07 | 2017-05-02 | View | |
85004 | CVE-2017-7983 | In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), mail sent using the JMail API leaked the used PHPMailer version in the mail headers. | 2 | 5 | Medium | 2017-05-07 | 2017-05-03 | View | |
85003 | CVE-2017-7982 | Integer overflow in the plist_from_bin function in bplist.c in libimobiledevice/libplist before 2017-04-19 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted plist file. | 2 | 4.3 | Medium | 2017-04-27 | 2017-04-25 | View | |
85499 | CVE-2017-7981 | Tuleap before 9.7 allows command injection via the PhpWiki 1.3.10 SyntaxHighlighter plugin. This occurs in the Project Wiki component because the proc_open PHP function is used within PhpWiki before 1.5.5 with a syntax value in its first argument, and an authenticated Tuleap user can control this value, even with shell metacharacters, as demonstrated by a '<?plugin SyntaxHighlighter syntax=c;id' line to execute the id command. | 2 | 9 | High | 2017-05-27 | 2017-05-11 | View | |
85002 | CVE-2017-7979 | The cookie feature in the packet action API implementation in net/sched/act_api.c in the Linux kernel 4.11.x through 4.11-rc7 mishandles the tb nlattr array, which allows local users to cause a denial of service (uninitialized memory access and refcount underflow, and system hang or crash) or possibly have unspecified other impact via tc filter add commands in certain contexts. NOTE: this does not affect stable kernels, such as 4.10.x, from kernel.org. | 2 | 7.2 | High | 2017-04-27 | 2017-04-25 | View |
Page 208 of 17672, showing 5 records out of 88360 total, starting on record 1036, ending on 1040