NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
85560  CVE-2017-8388  GeniXCMS 1.0.2 allows remote attackers to bypass the alertDanger MSG_USER_EMAIL_EXIST protection mechanism via a register.php?act=edit&id=1 request.    Medium  2017-05-27  2017-05-11  View
85559  CVE-2017-8385  Craft CMS before 2.6.2976 does not prevent modification of the URL in a forgot-password email message.    Medium  2017-05-27  2017-05-11  View
85558  CVE-2017-8384  Craft CMS before 2.6.2976 allows XSS attacks because an array returned by HttpRequestService::getSegments() and getActionSegments() need not be zero-based. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-8052.    4.3  Medium  2017-05-27  2017-05-11  View
85557  CVE-2017-8383  Craft CMS before 2.6.2976 does not properly restrict viewing the contents of files in the craft/app/ folder.    Medium  2017-05-27  2017-05-11  View
85556  CVE-2017-8378  Heap-based buffer overflow in the PdfParser::ReadObjects function in base/PdfParser.cpp in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via vectors related to m_offsets.size.    7.5  High  2017-05-27  2017-05-10  View

Page 561 of 17672, showing 5 records out of 88360 total, starting on record 2801, ending on 2805

Actions