NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
7114  CVE-2017-5345  SQL injection vulnerability in inc/lib/Control/Ajax/tags-ajax.control.php in GeniXCMS 0.0.8 allows remote authenticated editors to execute arbitrary SQL commands via the term parameter to the default URI.    6.5  Medium  2017-01-30  2017-01-27  View
82580  CVE-2017-5344  An issue was discovered in dotCMS through 3.6.1. The findChildrenByFilter() function which is called by the web accessible path /categoriesServlet performs string interpolation and direct SQL query execution. SQL quote escaping and a keyword blacklist were implemented in a new class, SQLUtil (main/java/com/dotmarketing/common/util/SQLUtil.java), as part of the remediation of CVE-2016-8902; however, these can be overcome in the case of the q and inode parameters to the /categoriesServlet path. Overcoming these controls permits a number of blind boolean SQL injection vectors in either parameter. The /categoriesServlet web path can be accessed remotely and without authentication in a default dotCMS deployment.    7.5  High  2017-03-18  2017-03-06  View
81629  CVE-2017-5342  In tcpdump before 4.9.0, a bug in multiple protocol parsers (Geneve, GRE, NSH, OTV, VXLAN and VXLAN GPE) could cause a buffer overflow in print-ether.c:ether_print().    7.5  High  2017-07-18  2017-06-30  View
81628  CVE-2017-5341  The OTV parser in tcpdump before 4.9.0 has a buffer overflow in print-otv.c:otv_print().    7.5  High  2017-07-18  2017-06-30  View
7113  CVE-2017-5340  Zend/zend_hash.c in PHP before 7.0.15 and 7.1.x before 7.1.1 mishandles certain cases that require large array allocations, which allows remote attackers to execute arbitrary code or cause a denial of service (integer overflow, uninitialized memory access, and use of arbitrary destructor function pointers) via crafted serialized data.    7.5  High  2017-01-19  2017-01-12  View

Page 486 of 17672, showing 5 records out of 88360 total, starting on record 2426, ending on 2430

Actions