NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
86677 | CVE-2017-9431 | Google gRPC before 2017-04-05 has an out-of-bounds write caused by a heap-based buffer overflow related to core/lib/iomgr/error.c. | 2 | 7.5 | High | 2017-06-17 | 2017-06-12 | View | |
86676 | CVE-2017-9430 | Stack-based buffer overflow in dnstracer through 1.9 allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a command line with a long name argument that is mishandled in a strcpy call for argv[0]. An example threat model is a web application that launches dnstracer with an untrusted name string. | 2 | 7.5 | High | 2017-06-17 | 2017-06-13 | View | |
87091 | CVE-2017-9429 | SQL injection vulnerability in the Event List plugin 0.7.8 for WordPress allows an authenticated user to execute arbitrary SQL commands via the id parameter to wp-admin/admin.php. | 2 | 6.5 | Medium | 2017-06-23 | 2017-06-20 | View | |
86675 | CVE-2017-9428 | A directory traversal vulnerability exists in coreadminajaxdeveloperextensionsfile-browser.php in BigTree CMS through 4.2.18 on Windows, allowing attackers to read arbitrary files via .. sequences in the directory parameter. | 2 | 5 | Medium | 2017-06-12 | 2017-06-06 | View | |
86674 | CVE-2017-9427 | SQL injection vulnerability in BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary SQL commands via coreadminmodulesdevelopermodulesdesignerform-create.php. The attacker creates a crafted table name at admin/developer/modules/designer/ and the injection is visible at admin/dashboard/vitals-statistics/integrity/check/?external=true. | 2 | 6.5 | Medium | 2017-06-12 | 2017-06-06 | View |
Page 59 of 17672, showing 5 records out of 88360 total, starting on record 291, ending on 295