NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
84943 | CVE-2017-7725 | concrete5 8.1.0 places incorrect trust in the HTTP Host header during caching, if the administrator did not define a canonical URL on installation of concrete5 using the Advanced Options settings. Remote attackers can make a GET request with any domain name in the Host header; this is stored and allows for arbitrary domains to be set for certain links displayed to subsequent visitors, potentially an XSS vector. | 2 | 4.3 | Medium | 2017-04-27 | 2017-04-20 | View | |
84942 | CVE-2017-7723 | XSS exists in Easy WP SMTP (before 1.2.5), a WordPress Plugin, via the e-mail subject or body. | 2 | 4.3 | Medium | 2017-06-03 | 2017-06-01 | View | |
84941 | CVE-2017-7722 | In SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4, a menu system is encountered when the SSH service is accessed with cmc and password (the default username and password). By exploiting a vulnerability in the restrictssh feature of the menuing script, an attacker can escape from the restricted shell. | 2 | 10 | High | 2017-04-27 | 2017-04-21 | View | |
85488 | CVE-2017-7721 | IrfanView version 4.44 (32bit) with FPX Plugin before 4.45 has an Access Violation and crash in processing a FlashPix (.FPX) file. | 2 | 6.8 | Medium | 2017-07-18 | 2017-07-11 | View | |
84940 | CVE-2017-7720 | Buffer overflow in PrivateTunnel 2.7 and 2.8 allows local attackers to cause a denial of service (SEH overwrite) or possibly have unspecified other impact via a long password. | 2 | 4.6 | Medium | 2017-05-07 | 2017-05-03 | View |
Page 230 of 17672, showing 5 records out of 88360 total, starting on record 1146, ending on 1150