NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
88092  CVE-2017-7681  Apache OpenMeetings 1.0.0 is vulnerable to SQL injection. This allows authenticated users to modify the structure of the existing query and leak the structure of other queries being made by the application in the back-end.          2017-07-18  2017-07-17  View
88091  CVE-2017-7680  Apache OpenMeetings 1.0.0 has an overly permissive crossdomain.xml file. This allows for flash content to be loaded from untrusted domains.          2017-07-18  2017-07-17  View
87301  CVE-2017-7679  In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_mime can read one byte past the end of a buffer when sending a malicious Content-Type response header.    7.5  High  2017-07-18  2017-07-06  View
88090  CVE-2017-7678  In Apache Spark before 2.2.0, it is possible for an attacker to take advantage of a user's trust in the server to trick them into visiting a link that points to a shared Spark cluster and submits data including MHTML to the Spark master, or history server. This data, which could contain a script, would then be reflected back to the user and could be evaluated and executed by MS Windows-based clients. It is not an attack on Spark itself, but on the user, who may then execute the script inadvertently when viewing elements of the Spark web UIs.          2017-07-18  2017-07-12  View
86991  CVE-2017-7677  In environments that use external location for hive tables, Hive Authorizer in Apache Ranger before 0.7.1 should be checking RWX permission for create table.    4.3  Medium  2017-06-23  2017-06-19  View

Page 236 of 17672, showing 5 records out of 88360 total, starting on record 1176, ending on 1180

Actions