NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
85796  CVE-2017-0890  Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.    3.5  Low  2017-05-27  2017-05-17  View
86052  CVE-2017-7952  INFOR EAM V11.0 Build 201410 has SQL injection via search fields, related to the filtervalue parameter.    6.5  Medium  2017-05-27  2017-05-24  View
86308  CVE-2017-9227  An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A stack out-of-bounds read occurs in mbc_enc_len() during regular expression searching. Invalid handling of reg->dmin in forward_search_range() could result in an invalid pointer dereference, as an out-of-bounds read from a stack buffer.    7.5  High  2017-06-03  2017-06-02  View
86564  CVE-2016-8741  The Apache Qpid Broker for Java can be configured to use different so called AuthenticationProviders to handle user authentication. Among the choices are the SCRAM-SHA-1 and SCRAM-SHA-256 AuthenticationProvider types. It was discovered that these AuthenticationProviders in Apache Qpid Broker for Java 6.0.x before 6.0.6 and 6.1.x before 6.1.1 prematurely terminate the SCRAM SASL negotiation if the provided user name does not exist thus allowing remote attacker to determine the existence of user accounts. The Vulnerability does not apply to AuthenticationProviders other than SCRAM-SHA-1 and SCRAM-SHA-256.    Medium  2017-06-04  2017-05-31  View
86820  CVE-2016-5960  IBM Security Privileged Identity Manager 2.0.2 and 2.1.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 116171.    2.1  Low  2017-06-18  2017-06-13  View

Page 528 of 17672, showing 5 records out of 88360 total, starting on record 2636, ending on 2640

Actions