NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
83860 | CVE-2017-7272 | PHP through 7.1.3 enables potential SSRF in applications that accept an fsockopen hostname argument with an expectation that the port number is constrained. Because a :port syntax is recognized, fsockopen will use the port number that is specified in the hostname argument, instead of the port number in the second argument of the function. | 2 | 5.8 | Medium | 2017-07-18 | 2017-07-11 | View | |
83859 | CVE-2017-7271 | Reflected Cross-site scripting (XSS) vulnerability in Yii Framework before 2.0.11, when development mode is used, allows remote attackers to inject arbitrary web script or HTML via crafted request data that is mishandled on the debug-mode exception screen. | 2 | 4.3 | Medium | 2017-05-27 | 2017-05-07 | View | |
83858 | CVE-2017-7269 | Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server 2003 R2 allows remote attackers to execute arbitrary code via a long header beginning with If: <http:// in a PROPFIND request, as exploited in the wild in July or August 2016. | 2 | 10 | High | 2017-07-18 | 2017-07-11 | View | |
83857 | CVE-2017-7266 | Netflix Security Monkey before 0.8.0 has an Open Redirect. The logout functionality accepted the next parameter which then redirects to any domain irrespective of the Host header. | 2 | 5.8 | Medium | 2017-03-29 | 2017-03-28 | View | |
83856 | CVE-2017-7264 | Use-after-free vulnerability in the fz_subsample_pixmap function in fitz/pixmap.c in Artifex Software, Inc. MuPDF 1.10a allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted document. | 2 | 6.8 | Medium | 2017-03-29 | 2017-03-28 | View |
Page 901 of 17672, showing 5 records out of 88360 total, starting on record 4501, ending on 4505