NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
87409  CVE-2017-9836  Cross-site scripting (XSS) vulnerability in Piwigo 2.9.1 allows remote authenticated administrators to inject arbitrary web script or HTML via the virtual_name parameter to /admin.php (i.e., creating a virtual album).    3.5  Low  2017-06-28  2017-06-27  View
87408  CVE-2017-9833  /cgi-bin/wapopen in BOA Webserver 0.94.14rc21 allows the injection of ../.. using the FILECAMERA variable (sent by GET) to read files with root privileges.    Medium  2017-07-18  2017-07-03  View
87407  CVE-2017-9832  An integer overflow vulnerability in ptp-pack.c (ptp_unpack_OPL function) of libmtp (version 1.1.12 and below) allows attackers to cause a denial of service (out-of-bounds memory access) or maybe remote code execution by inserting a mobile device into a personal computer through a USB cable.    4.6  Medium  2017-07-18  2017-06-29  View
87406  CVE-2017-9831  An integer overflow vulnerability in the ptp_unpack_EOS_CustomFuncEx function of the ptp-pack.c file of libmtp (version 1.1.12 and below) allows attackers to cause a denial of service (out-of-bounds memory access) or maybe remote code execution by inserting a mobile device into a personal computer through a USB cable.    4.6  Medium  2017-07-18  2017-06-29  View
87405  CVE-2017-9830  Remote Code Execution is possible in Code42 CrashPlan 5.4.x via the org.apache.commons.ssl.rmi.DateRMI Java class, because (upon instantiation) it creates an RMI server that listens on a TCP port and deserializes objects sent by TCP clients.    7.5  High  2017-07-18  2017-07-05  View

Page 21 of 17672, showing 5 records out of 88360 total, starting on record 101, ending on 105

Actions