NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
87753  CVE-2017-10976  When SWFTools 0.9.2 processes a crafted file in ttftool, it can lead to a heap-based buffer over-read in the readBlock() function in lib/ttf.c.    Medium  2017-07-18  2017-07-17  View
87752  CVE-2017-10975  Cross-site scripting (XSS) vulnerability in Lutim before 0.8 might allow remote attackers to inject arbitrary web script or HTML via a crafted filename that is mishandled in an upload notification and in the myfiles component, if the attacker can convince the victim to proceed with an upload despite the appearance of an XSS payload in the filename.    4.3  Medium  2017-07-18  2017-07-17  View
87751  CVE-2017-10974  Yaws 1.91 allows Unauthenticated Remote File Disclosure via HTTP Directory Traversal with /%5C../ to port 8080. NOTE: this CVE is only about use of an initial /%5C sequence to defeat traversal protection mechanisms; the initial /%5C sequence was apparently not discussed in earlier research on this product.    Medium  2017-07-18  2017-07-14  View
87750  CVE-2017-10973  In FineCMS before 2017-07-06, application/lib/ajax/get_image_data.php has SSRF, related to requests for non-image files with a modified HTTP Host header.    4.3  Medium  2017-07-18  2017-07-17  View
87749  CVE-2017-10972  Uninitialized data in endianness conversion in the XEvent handling of the X.Org X Server before 2017-06-19 allowed authenticated malicious users to access potentially privileged data from the X server.          2017-07-18  2017-07-17  View

Page 810 of 17672, showing 5 records out of 88360 total, starting on record 4046, ending on 4050

Actions