NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
86687 | CVE-2017-9441 | ** DISPUTED ** Multiple cross-site scripting (XSS) vulnerabilities in BigTree CMS through 4.2.18 allow remote authenticated users to inject arbitrary web script or HTML by uploading a crafted package, triggering mishandling of the (1) title or (2) version or (3) author_name parameter in manifest.json. This issue exists in coreadminmodulesdeveloperextensionsinstallunpack.php and coreadminmodulesdeveloperpackagesinstallunpack.php. NOTE: the vendor states You must implicitly trust any package or extension you install as they all have the ability to write PHP files. | 2 | 3.5 | Low | 2017-06-17 | 2017-06-12 | View | |
86686 | CVE-2017-9440 | In ImageMagick 7.0.5-5, a memory leak was found in the function ReadPSDChannel in coders/psd.c, which allows attackers to cause a denial of service via a crafted file. | 2 | 4.3 | Medium | 2017-06-12 | 2017-06-09 | View | |
86685 | CVE-2017-9439 | In ImageMagick 7.0.5-5, a memory leak was found in the function ReadPDBImage in coders/pdb.c, which allows attackers to cause a denial of service via a crafted file. | 2 | 4.3 | Medium | 2017-06-12 | 2017-06-09 | View | |
86684 | CVE-2017-9438 | libyara/re.c in the regexp module in YARA 3.5.0 allows remote attackers to cause a denial of service (stack consumption) via a crafted rule (involving hex strings) that is mishandled in the _yr_re_emit function, a different vulnerability than CVE-2017-9304. | 2 | 5 | Medium | 2017-06-12 | 2017-06-06 | View | |
86683 | CVE-2017-9437 | Openbravo Business Suite 3.0 is affected by SQL injection. This vulnerability could allow remote authenticated attackers to inject arbitrary SQL code. | 2 | 6.5 | Medium | 2017-06-17 | 2017-06-13 | View |
Page 57 of 17672, showing 5 records out of 88360 total, starting on record 281, ending on 285