NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
17430  CVE-2016-10045  The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code by leveraging improper interaction between the escapeshellarg function and internal escaping performed in the mail function in PHP. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-10033.    7.5  High  2017-01-30  2017-01-25  View
18826  CVE-2016-2842  The doapr_outch function in crypto/bio/b_print.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g does not verify that a certain memory allocation succeeds, which allows remote attackers to cause a denial of service (out-of-bounds write or memory consumption) or possibly have unspecified other impact via a long string, as demonstrated by a large amount of ASN.1 data, a different vulnerability than CVE-2016-0799.    10  High  2017-01-30  2017-01-25  View
20415  CVE-2016-4994  Use-after-free vulnerability in the xcf_load_image function in app/xcf/xcf-load.c in GIMP allows remote attackers to cause a denial of service (program crash) or possibly execute arbitrary code via a crafted XCF file.    6.8  Medium  2017-01-30  2017-01-25  View
7121  CVE-2017-5474  Open redirect vulnerability in comment.php in Serendipity through 2.0.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the HTTP Referer header.    5.8  Medium  2017-01-30  2017-01-25  View
7122  CVE-2017-5475  comment.php in Serendipity through 2.0.5 allows CSRF in deleting any comments.    6.8  Medium  2017-01-30  2017-01-25  View

Page 2365 of 17672, showing 5 records out of 88360 total, starting on record 11821, ending on 11825

Actions