NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
85508  CVE-2017-8114  Roundcube Webmail allows arbitrary password resets by authenticated users. This affects versions before 1.0.11, 1.1.x before 1.1.9, and 1.2.x before 1.2.5. The problem is caused by an improperly restricted exec call in the virtualmin and sasl drivers of the password plugin.    6.5  Medium  2017-07-18  2017-07-10  View
86020  CVE-2017-7472  The KEYS subsystem in the Linux kernel before 4.10.13 allows local users to cause a denial of service (memory consumption) via a series of KEY_REQKEY_DEFL_THREAD_KEYRING keyctl_set_reqkey_keyring calls.    4.9  Medium  2017-07-18  2017-07-07  View
87300  CVE-2017-7668  The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which allows ap_find_token() to search past the end of its input string. By maliciously crafting a sequence of request headers, an attacker may be able to cause a segmentation fault, or to force ap_find_token() to return an incorrect value.    7.5  High  2017-07-18  2017-07-06  View
87556  CVE-2017-1000016  A weakness was discovered where an attacker can inject arbitrary values in to the browser cookies. This is a re-issue of an incomplete fix from PMASA-2016-18.          2017-07-18  2017-07-17  View
87812  CVE-2017-11180  FineCMS through 2017-07-11 has stored XSS in the logging functionality, as demonstrated by an XSS payload in (1) the User-Agent header of an HTTP request or (2) the username entered on the login screen.    4.3  Medium  2017-07-18  2017-07-16  View

Page 29 of 17672, showing 5 records out of 88360 total, starting on record 141, ending on 145

Actions