NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
86696 | CVE-2017-9462 | In Mercurial before 4.1.3, hg serve --stdio allows remote authenticated users to launch the Python debugger, and consequently execute arbitrary code, by using --debugger as a repository name. | 2 | 9 | High | 2017-06-23 | 2017-06-20 | View | |
86695 | CVE-2017-9461 | smbd in Samba before 4.4.10 and 4.5.x before 4.5.6 has a denial of service vulnerability (fd_open_atomic infinite loop with high CPU usage and memory consumption) due to wrongly handling dangling symlinks. | 2 | 7.8 | High | 2017-06-17 | 2017-06-15 | View | |
86694 | CVE-2017-9452 | Cross-site scripting (XSS) vulnerability in admin.php in Piwigo 2.9.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the page parameter. | 2 | 3.5 | Low | 2017-06-12 | 2017-06-09 | View | |
86693 | CVE-2017-9451 | Cross site scripting (XSS) vulnerability in pages.edit_form.php in flatCore 1.4.6 allows remote attackers to inject arbitrary JavaScript via the PATH_INFO in an acp.php URL, due to use of unsanitized $_SERVER['PHP_SELF'] to generate URLs. | 2 | 4.3 | Medium | 2017-06-17 | 2017-06-13 | View | |
86692 | CVE-2017-9449 | SQL injection vulnerability in BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary SQL commands via core/admin/modules/developer/modules/views/create.php. The attacker creates a crafted table name at admin/developer/modules/views/create/ and the injection is visible at admin/ajax/auto-modules/views/searchable-page/ or admin/modules_name. | 2 | 6.5 | Medium | 2017-06-17 | 2017-06-12 | View |
Page 55 of 17672, showing 5 records out of 88360 total, starting on record 271, ending on 275