NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
83756 | CVE-2017-6003 | dotCMS 3.7.0 has XSS reachable from ext/languages_manager/edit_language in portal/layout via the bottom two form fields. | 2 | 4.3 | Medium | 2017-03-29 | 2017-03-28 | View | |
83755 | CVE-2017-6002 | Subrion CMS 4.0.5.10 has CSRF in admin/blog/add/. The attacker can add any blog entry, and can optionally insert XSS into that entry via the body parameter. | 2 | 6.8 | Medium | 2017-03-29 | 2017-03-28 | View | |
82595 | CVE-2017-6001 | Race condition in kernel/events/core.c in the Linux kernel before 4.9.7 allows local users to gain privileges via a crafted application that makes concurrent perf_event_open system calls for moving a software group into a hardware context. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-6786. | 2 | 7.6 | High | 2017-03-18 | 2017-03-01 | View | |
82594 | CVE-2017-6000 | ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none. | 1 | 2017-02-28 | 2017-02-16 | View | |||
83279 | CVE-2017-5999 | An issue was discovered in sysPass 2.x before 2.1, in which an algorithm was never sufficiently reviewed by cryptographers. The fact that inc/SP/Core/Crypt.class is using the MCRYPT_RIJNDAEL_256() function (the 256-bit block version of Rijndael, not AES) instead of MCRYPT_RIJNDAEL_128 (real AES) could help an attacker to create unknown havoc in the remote system. | 2 | 5 | Medium | 2017-03-18 | 2017-03-15 | View |
Page 419 of 17672, showing 5 records out of 88360 total, starting on record 2091, ending on 2095