NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
87753 | CVE-2017-10976 | When SWFTools 0.9.2 processes a crafted file in ttftool, it can lead to a heap-based buffer over-read in the readBlock() function in lib/ttf.c. | 2 | 5 | Medium | 2017-07-18 | 2017-07-17 | View | |
87752 | CVE-2017-10975 | Cross-site scripting (XSS) vulnerability in Lutim before 0.8 might allow remote attackers to inject arbitrary web script or HTML via a crafted filename that is mishandled in an upload notification and in the myfiles component, if the attacker can convince the victim to proceed with an upload despite the appearance of an XSS payload in the filename. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-17 | View | |
87751 | CVE-2017-10974 | Yaws 1.91 allows Unauthenticated Remote File Disclosure via HTTP Directory Traversal with /%5C../ to port 8080. NOTE: this CVE is only about use of an initial /%5C sequence to defeat traversal protection mechanisms; the initial /%5C sequence was apparently not discussed in earlier research on this product. | 2 | 5 | Medium | 2017-07-18 | 2017-07-14 | View | |
87750 | CVE-2017-10973 | In FineCMS before 2017-07-06, application/lib/ajax/get_image_data.php has SSRF, related to requests for non-image files with a modified HTTP Host header. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-17 | View | |
87749 | CVE-2017-10972 | Uninitialized data in endianness conversion in the XEvent handling of the X.Org X Server before 2017-06-19 allowed authenticated malicious users to access potentially privileged data from the X server. | 2017-07-18 | 2017-07-17 | View |
Page 810 of 17672, showing 5 records out of 88360 total, starting on record 4046, ending on 4050