NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
86540 | CVE-2017-9380 | OpenEMR 5.0.0 and prior allows low-privilege users to upload files of dangerous types which can result in arbitrary code execution within the context of the vulnerable application. | 2 | 6.5 | Medium | 2017-06-12 | 2017-06-08 | View | |
86539 | CVE-2017-9379 | Multiple CSRF issues exist in BigTree CMS through 4.2.18 - the clear parameter to coreadminmodulesdashboardvitals-statistics404clear.php and the from or to parameter to coreadminmodulesdashboardvitals-statistics404create-301.php. | 2 | 6.8 | Medium | 2017-06-12 | 2017-06-06 | View | |
86538 | CVE-2017-9378 | BigTree CMS through 4.2.18 does not prevent a user from deleting their own account. This could have security relevance because deletion was supposed to be an admin-only action, and the admin may have other tasks (such as data backups) to complete before a user is deleted. | 2 | 4 | Medium | 2017-06-12 | 2017-06-06 | View | |
86537 | CVE-2017-9372 | PJSIP, as used in Asterisk Open Source 13.x before 13.15.1 and 14.x before 14.4.1, Certified Asterisk 13.13 before 13.13-cert4, and other products, allows remote attackers to cause a denial of service (buffer overflow and application crash) via a SIP packet with a crafted CSeq header in conjunction with a Via header that lacks a branch parameter. | 2 | 5 | Medium | 2017-07-18 | 2017-07-07 | View | |
86536 | CVE-2017-9366 | Telaxus EPESI 1.8.2 and earlier has a Stored Cross-site Scripting (XSS) vulnerability in modules/Base/Dashboard/Dashboard_0.php, which allows remote attackers to inject arbitrary web script or HTML via a crafted tab_name parameter. | 2 | 3.5 | Low | 2017-06-12 | 2017-06-09 | View |
Page 365 of 17672, showing 5 records out of 88360 total, starting on record 1821, ending on 1825