NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
84843  CVE-2017-7418  ProFTPD before 1.3.5e and 1.3.6 before 1.3.6rc5 controls whether the home directory of a user could contain a symbolic link through the AllowChrootSymlinks configuration option, but checks only the last path component when enforcing AllowChrootSymlinks. Attackers with local access could bypass the AllowChrootSymlinks control by replacing a path component (other than the last one) with a symbolic link. The threat model includes an attacker who is not granted full filesystem access by a hosting provider, but can reconfigure the home directory of an FTP user.    2.1  Low  2017-04-27  2017-04-11  View
87380  CVE-2017-7416  ntopng before 3.0 allows XSS because GET and POST parameters are improperly validated.    4.3  Medium  2017-07-18  2017-06-29  View
85225  CVE-2017-7415  Atlassian Confluence 6.x before 6.0.7 allows remote attackers to bypass authentication and read any blog or page via the drafts diff REST resource.    Medium  2017-05-27  2017-05-09  View
84842  CVE-2017-7414  In Horde_Crypt before 2.7.6, as used in Horde Groupware Webmail Edition 5.x through 5.2.17, OS Command Injection can occur if the user has PGP features enabled in the user's preferences, and has enabled the Should PGP signed messages be automatically verified when viewed? preference. To exploit this vulnerability, an attacker can send a PGP signed email (that is maliciously crafted) to the Horde user, who then must either view or preview it.    5.1  Medium  2017-04-27  2017-04-12  View
84841  CVE-2017-7413  In Horde_Crypt before 2.7.6, as used in Horde Groupware Webmail Edition through 5.2.17, OS Command Injection can occur if the attacker is an authenticated Horde Webmail user, has PGP features enabled in their preferences, and attempts to encrypt an email addressed to a maliciously crafted email address.    High  2017-04-27  2017-04-11  View

Page 266 of 17672, showing 5 records out of 88360 total, starting on record 1326, ending on 1330

Actions