NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
80708  CVE-2002-1757  PHProjekt 2.0 through 3.1 relies on the $PHP_SELF variable for authentication, which allows remote attackers to bypass authentication for scripts via a request to a .php file with sms in the URL, which is included in the PATH_INFO portion of the $PHP_SELF variable, as demonstrated using mail_send.php/sms.    7.5  High  2017-07-18  2017-07-10  View
81476  CVE-2017-3316  Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: GUI). Supported versions that are affected are VirtualBox prior to 5.0.32 and prior to 5.1.14. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS v3.0 Base Score 8.4 (Confidentiality, Integrity and Availability impacts).    Medium  2017-07-18  2017-06-30  View
82244  CVE-2017-5839  The gst_riff_create_audio_caps function in gst-libs/gst/riff/riff-media.c in gst-plugins-base in GStreamer before 1.10.3 does not properly limit recursion, which allows remote attackers to cause a denial of service (stack overflow and crash) via vectors involving nested WAVEFORMATEX.    Medium  2017-07-18  2017-06-30  View
83012  CVE-2017-0105  Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word for Mac 2011, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allow remote attackers to obtain sensitive information from out-of-bound memory via a crafted Office document, aka Microsoft Office Information Disclosure Vulnerability.    4.3  Medium  2017-07-18  2017-07-11  View
84292  CVE-2017-2415  An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the WebKit component. It allows remote attackers to execute arbitrary code by leveraging an unspecified type confusion.    6.8  Medium  2017-07-18  2017-07-11  View

Page 385 of 17672, showing 5 records out of 88360 total, starting on record 1921, ending on 1925

Actions