NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
85069  CVE-2017-8291  Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a /OutputFile (%pipe% substring in a crafted .eps document that is an input to the gs program, as exploited in the wild in April 2017.    6.8  Medium  2017-05-27  2017-05-26  View
85325  CVE-2016-4896  SetsucoCMS all versions does not properly manage sessions, which allows remote attackers to disclose or alter unauthorized information via unspecified vectors.    6.4  Medium  2017-05-27  2017-05-22  View
85581  CVE-2017-8760  An issue was discovered on Accellion FTA devices before FTA_9_12_180. There is XSS in courier/1000@/index.html with the auth_params parameter. The device tries to use internal WAF filters to stop specific XSS Vulnerabilities. However, these can be bypassed by using some modifications to the payloads, e.g., URL encoding.    4.3  Medium  2017-05-27  2017-05-17  View
85837  CVE-2017-2506  An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The issue involves the WebKit component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.    6.8  Medium  2017-07-18  2017-07-07  View
86093  CVE-2017-8847  The bufRead::get() function in libzpaq/libzpaq.h in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted archive.    4.3  Medium  2017-05-27  2017-05-16  View

Page 852 of 17672, showing 5 records out of 88360 total, starting on record 4256, ending on 4260

Actions