NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
88006 | CVE-2017-5944 | The dashboard subscription interface in Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 might allow remote authenticated users with certain privileges to execute arbitrary code via a crafted saved search name. | 2 | 6.5 | Medium | 2017-07-18 | 2017-07-07 | View | |
88005 | CVE-2017-5943 | Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 allows remote attackers to obtain sensitive information about cross-site request forgery (CSRF) verification tokens via a crafted URL. | 2 | 6.8 | Medium | 2017-07-18 | 2017-07-07 | View | |
82258 | CVE-2017-5942 | An issue was discovered in the WP Mail plugin before 1.2 for WordPress. The replyto parameter when composing a mail allows for a reflected XSS. This would allow you to execute JavaScript in the context of the user receiving the mail. | 2 | 4.3 | Medium | 2017-03-18 | 2017-02-28 | View | |
82257 | CVE-2017-5941 | An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() function can be exploited to achieve arbitrary code execution by passing a JavaScript Object with an Immediately Invoked Function Expression (IIFE). | 2 | 7.5 | High | 2017-03-18 | 2017-02-28 | View | |
82256 | CVE-2017-5940 | Firejail before 0.9.44.6 and 0.9.38.x LTS before 0.9.38.10 LTS does not comprehensively address dotfile cases during its attempt to prevent accessing user files with an euid of zero, which allows local users to conduct sandbox-escape attacks via vectors involving a symlink and the --private option. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-5180. | 2 | 4.6 | Medium | 2017-07-18 | 2017-06-30 | View |
Page 429 of 17672, showing 5 records out of 88360 total, starting on record 2141, ending on 2145