NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
86838  CVE-2016-7813  Cross-site scripting vulnerability in DERAEMON-CMS version 0.8.9 and earlier allows remote attackers to inject arbitrary web script or HTML via the parameters hostname, database and username.    4.3  Medium  2017-06-18  2017-06-16  View
87094  CVE-2017-9502  In curl before 7.54.1 on Windows and DOS, libcurl's default protocol function, which is the logic that allows an application to set which protocol libcurl should attempt to use when given a URL without a scheme part, had a flaw that could lead to it overwriting a heap based memory buffer with seven bytes. If the default protocol is specified to be FILE or a file: URL lacks two slashes, the given URL starts with a drive letter, and libcurl is built for Windows or DOS, then libcurl would copy the path 7 bytes off, so that the end of the given path would write beyond the malloc buffer (7 bytes being the length in bytes of the ascii string file://).    Medium  2017-07-18  2017-07-07  View
87350  CVE-2016-9983  IBM Sterling B2B Integrator Standard Edition 5.2 could allow an authenticated user with special privileges to view files that they should not have access to. IBM X-Force ID: 120275.    3.5  Low  2017-06-28  2017-06-26  View
87606  CVE-2017-1000069  CSRF in Bitly oauth2_proxy 2.1 during authentication flow          2017-07-18  2017-07-17  View
87862  CVE-2017-11416  Fiyo CMS 2.0.7 has SQL injection in /apps/app_comment/controller/insert.php via the name parameter.          2017-07-18  2017-07-18  View

Page 674 of 17672, showing 5 records out of 88360 total, starting on record 3366, ending on 3370

Actions