NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
86130 | CVE-2017-8914 | sinopia, as used in SAP HANA XS 1.00 and 2.00, allows remote attackers to hijack npm packages or host arbitrary files by leveraging an insecure user creation policy, aka SAP Security Note 2407694. | 2 | 7.5 | High | 2017-06-12 | 2017-06-08 | View | |
86129 | CVE-2017-8913 | The Visual Composer VC70RUNTIME component in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via a crafted XML document in a request to irj/servlet/prt/portal/prtroot/com.sap.visualcomposer.BIKit.default, aka SAP Security Note 2386873. | 2 | 6.5 | Medium | 2017-06-03 | 2017-06-01 | View | |
86128 | CVE-2017-8912 | ** DISPUTED ** CMS Made Simple (CMSMS) 2.1.6 allows remote authenticated administrators to execute arbitrary PHP code via the code parameter to admin/editusertag.php, related to the CreateTagFunction and CallUserTag functions. NOTE: the vendor reportedly has stated this is a feature, not a bug. | 2 | 6.5 | Medium | 2017-05-27 | 2017-05-17 | View | |
86127 | CVE-2017-8911 | An integer underflow has been identified in the unicode_to_utf8() function in tnef 1.4.14. This might lead to invalid write operations, controlled by an attacker. | 2 | 7.5 | High | 2017-05-27 | 2017-05-17 | View | |
86126 | CVE-2017-8908 | The mark_line_tr function in gxscanc.c in Artifex Ghostscript 9.21 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PostScript document. | 2 | 4.3 | Medium | 2017-05-27 | 2017-05-22 | View |
Page 447 of 17672, showing 5 records out of 88360 total, starting on record 2231, ending on 2235