NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
81642 | CVE-2017-5542 | Cross-site scripting (XSS) vulnerability in template/usererror.missing_extension.php in Symphony CMS before 2.6.10 allows remote attackers to inject arbitrary web script or HTML via the existing-folder parameter. | 2 | 4.3 | Medium | 2017-02-07 | 2017-01-26 | View | |
81641 | CVE-2017-5541 | Directory traversal vulnerability in template/usererror.missing_extension.php in Symphony CMS before 2.6.10 allows remote attackers to rename arbitrary files via a .. (dot dot) in the existing-folder and new-folder parameters. | 2 | 5 | Medium | 2017-02-07 | 2017-01-26 | View | |
81640 | CVE-2017-5539 | The patch for directory traversal (CVE-2017-5480) in b2evolution version 6.8.4-stable has a bypass vulnerability. An attacker can use ../ to bypass the filter rule. Then, this attacker can exploit this vulnerability to delete or read any files on the server. It can also be used to determine whether a file exists. | 2 | 9 | High | 2017-02-07 | 2017-01-26 | View | |
83735 | CVE-2017-5538 | The kbase_dispatch function in arm/t7xx/r5p0/mali_kbase_core_linux.c in the GPU driver on Samsung devices with M(6.0) and N(7.0) software and Exynos AP chipsets allows attackers to have unspecified impact via unknown vectors, which trigger an out-of-bounds read, aka SVE-2016-6362. | 2 | 10 | High | 2017-03-29 | 2017-03-28 | View | |
83213 | CVE-2017-5537 | The password reset form in Weblate before 2.10.1 provides different error messages depending on whether the email address is associated with an account, which allows remote attackers to enumerate user accounts via a series of requests. | 2 | 5 | Medium | 2017-03-29 | 2017-03-21 | View |
Page 472 of 17672, showing 5 records out of 88360 total, starting on record 2356, ending on 2360