NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
85560 | CVE-2017-8388 | GeniXCMS 1.0.2 allows remote attackers to bypass the alertDanger MSG_USER_EMAIL_EXIST protection mechanism via a register.php?act=edit&id=1 request. | 2 | 5 | Medium | 2017-05-27 | 2017-05-11 | View | |
85559 | CVE-2017-8385 | Craft CMS before 2.6.2976 does not prevent modification of the URL in a forgot-password email message. | 2 | 5 | Medium | 2017-05-27 | 2017-05-11 | View | |
85558 | CVE-2017-8384 | Craft CMS before 2.6.2976 allows XSS attacks because an array returned by HttpRequestService::getSegments() and getActionSegments() need not be zero-based. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-8052. | 2 | 4.3 | Medium | 2017-05-27 | 2017-05-11 | View | |
85557 | CVE-2017-8383 | Craft CMS before 2.6.2976 does not properly restrict viewing the contents of files in the craft/app/ folder. | 2 | 5 | Medium | 2017-05-27 | 2017-05-11 | View | |
85556 | CVE-2017-8378 | Heap-based buffer overflow in the PdfParser::ReadObjects function in base/PdfParser.cpp in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via vectors related to m_offsets.size. | 2 | 7.5 | High | 2017-05-27 | 2017-05-10 | View |
Page 561 of 17672, showing 5 records out of 88360 total, starting on record 2801, ending on 2805