NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
86838 | CVE-2016-7813 | Cross-site scripting vulnerability in DERAEMON-CMS version 0.8.9 and earlier allows remote attackers to inject arbitrary web script or HTML via the parameters hostname, database and username. | 2 | 4.3 | Medium | 2017-06-18 | 2017-06-16 | View | |
87094 | CVE-2017-9502 | In curl before 7.54.1 on Windows and DOS, libcurl's default protocol function, which is the logic that allows an application to set which protocol libcurl should attempt to use when given a URL without a scheme part, had a flaw that could lead to it overwriting a heap based memory buffer with seven bytes. If the default protocol is specified to be FILE or a file: URL lacks two slashes, the given URL starts with a drive letter, and libcurl is built for Windows or DOS, then libcurl would copy the path 7 bytes off, so that the end of the given path would write beyond the malloc buffer (7 bytes being the length in bytes of the ascii string file://). | 2 | 5 | Medium | 2017-07-18 | 2017-07-07 | View | |
87350 | CVE-2016-9983 | IBM Sterling B2B Integrator Standard Edition 5.2 could allow an authenticated user with special privileges to view files that they should not have access to. IBM X-Force ID: 120275. | 2 | 3.5 | Low | 2017-06-28 | 2017-06-26 | View | |
87606 | CVE-2017-1000069 | CSRF in Bitly oauth2_proxy 2.1 during authentication flow | 2017-07-18 | 2017-07-17 | View | ||||
87862 | CVE-2017-11416 | Fiyo CMS 2.0.7 has SQL injection in /apps/app_comment/controller/insert.php via the name parameter. | 2017-07-18 | 2017-07-18 | View |
Page 674 of 17672, showing 5 records out of 88360 total, starting on record 3366, ending on 3370