NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
86130  CVE-2017-8914  sinopia, as used in SAP HANA XS 1.00 and 2.00, allows remote attackers to hijack npm packages or host arbitrary files by leveraging an insecure user creation policy, aka SAP Security Note 2407694.    7.5  High  2017-06-12  2017-06-08  View
86129  CVE-2017-8913  The Visual Composer VC70RUNTIME component in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via a crafted XML document in a request to irj/servlet/prt/portal/prtroot/com.sap.visualcomposer.BIKit.default, aka SAP Security Note 2386873.    6.5  Medium  2017-06-03  2017-06-01  View
86128  CVE-2017-8912  ** DISPUTED ** CMS Made Simple (CMSMS) 2.1.6 allows remote authenticated administrators to execute arbitrary PHP code via the code parameter to admin/editusertag.php, related to the CreateTagFunction and CallUserTag functions. NOTE: the vendor reportedly has stated this is a feature, not a bug.    6.5  Medium  2017-05-27  2017-05-17  View
86127  CVE-2017-8911  An integer underflow has been identified in the unicode_to_utf8() function in tnef 1.4.14. This might lead to invalid write operations, controlled by an attacker.    7.5  High  2017-05-27  2017-05-17  View
86126  CVE-2017-8908  The mark_line_tr function in gxscanc.c in Artifex Ghostscript 9.21 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PostScript document.    4.3  Medium  2017-05-27  2017-05-22  View

Page 447 of 17672, showing 5 records out of 88360 total, starting on record 2231, ending on 2235

Actions