NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
85585  CVE-2017-8768  Atlassian SourceTree v2.5c and prior are affected by a command injection in the handling of the sourcetree:// scheme. It will lead to arbitrary OS command execution with a URL substring of sourcetree://cloneRepo/ext:: or sourcetree://checkoutRef/ext:: followed by the command. The Atlassian ID number is SRCTREE-4632.    10  High  2017-05-27  2017-05-17  View
85584  CVE-2017-8765  The function named ReadICONImage in codersicon.c in ImageMagick 7.0.5-5 has a memory leak vulnerability which can cause memory exhaustion via a crafted ICON file.    7.1  High  2017-06-03  2017-05-31  View
85583  CVE-2017-8763  Cross-site scripting (XSS) vulnerability in modules/Base/Box/check_for_new_version.php in EPESI in Telaxus/EPESI 1.8.2 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted URI that lacks the cid parameter.    4.3  Medium  2017-05-27  2017-05-15  View
85582  CVE-2017-8762  GeniXCMS 1.0.2 has XSS triggered by an authenticated user who submits a page, as demonstrated by a crafted oncut attribute in a B element.    3.5  Low  2017-05-27  2017-05-12  View
85581  CVE-2017-8760  An issue was discovered on Accellion FTA devices before FTA_9_12_180. There is XSS in courier/1000@/index.html with the auth_params parameter. The device tries to use internal WAF filters to stop specific XSS Vulnerabilities. However, these can be bypassed by using some modifications to the payloads, e.g., URL encoding.    4.3  Medium  2017-05-27  2017-05-17  View

Page 556 of 17672, showing 5 records out of 88360 total, starting on record 2776, ending on 2780

Actions