NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
83837  CVE-2017-7235  An issue was discovered in cloudflare-scrape 1.6.6 through 1.7.1. A malicious website owner could craft a page that executes arbitrary Python code against any cfscrape user who scrapes that website. This is fixed in 1.8.0.    6.8  Medium  2017-04-27  2017-03-30  View
84778  CVE-2017-7234  A maliciously crafted URL to a Django (1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18) site using the ``django.views.static.serve()`` view could redirect to any other domain, aka an open redirect vulnerability.    5.8  Medium  2017-07-18  2017-07-11  View
84777  CVE-2017-7233  Django 1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18 relies on user input in some cases to redirect the user to an on success URL. The security check for these redirects (namely ``django.utils.http.is_safe_url()``) considered some numeric URLs safe when they shouldn't be, aka an open redirect vulnerability. Also, if a developer relies on ``is_safe_url()`` to provide safe redirect targets and puts such a URL into a link, they could suffer from an XSS attack.    5.8  Medium  2017-07-18  2017-07-11  View
83836  CVE-2017-7231  pngdefry through 2017-03-22 is prone to a heap-based buffer-overflow vulnerability because it fails to properly process a specially crafted png file. This issue affects the 'process()' function of the 'pngdefry.c' source file.    6.8  Medium  2017-03-29  2017-03-28  View
83835  CVE-2017-7230  A buffer overflow vulnerability in Disk Sorter Enterprise 9.5.12 and earlier allows remote attackers to execute arbitrary code via a GET request.    7.5  High  2017-04-27  2017-03-30  View

Page 293 of 17672, showing 5 records out of 88360 total, starting on record 1461, ending on 1465

Actions