NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
84995  CVE-2017-7961  ** DISPUTED ** The cr_tknzr_parse_rgb function in cr-tknzr.c in libcroco 0.6.11 and 0.6.12 has an outside the range of representable values of type long undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted CSS file. NOTE: third-party analysis reports This is not a security issue in my view. The conversion surely is truncating the double into a long value, but there is no impact as the value is one of the RGB components.    6.8  Medium  2017-07-18  2017-07-10  View
84994  CVE-2017-7960  The cr_input_new_from_uri function in cr-input.c in libcroco 0.6.11 and 0.6.12 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted CSS file.    4.3  Medium  2017-07-18  2017-07-10  View
85498  CVE-2017-7957  XStream through 1.4.9, when a certain denyTypes workaround is not used, mishandles attempts to create an instance of the primitive type 'void' during unmarshalling, leading to a remote application crash, as demonstrated by an xstream.fromXML(<void/>) call.    Medium  2017-05-27  2017-05-09  View
86053  CVE-2017-7953  INFOR EAM V11.0 Build 201410 has XSS via comment fields.    3.5  Low  2017-05-27  2017-05-24  View
86052  CVE-2017-7952  INFOR EAM V11.0 Build 201410 has SQL injection via search fields, related to the filtervalue parameter.    6.5  Medium  2017-05-27  2017-05-24  View

Page 211 of 17672, showing 5 records out of 88360 total, starting on record 1051, ending on 1055

Actions