NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
87724  CVE-2017-10911  The make_response function in drivers/block/xen-blkback/blkback.c in the Linux kernel before 4.11.8 allows guest OS users to obtain sensitive information from host OS (or other guest OS) kernel memory by leveraging the copying of uninitialized padding fields in Xen block-interface response structures, aka XSA-216.    4.9  Medium  2017-07-18  2017-07-14  View
87980  CVE-2017-3103  Adobe Connect versions 9.6.1 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to a stored cross-site scripting attack.          2017-07-18  2017-07-17  View
88236  CVE-2017-9874  IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to a User Mode Write AV starting at FPX!FPX_GetScanDevicePropertyGroup+0x0000000000007822.    6.8  Medium  2017-07-18  2017-07-11  View
59820  CVE-2006-1098  ** DISPUTED ** Multiple SQL injection vulnerabilities in NZ Ecommerce allow remote attackers to execute arbitrary SQL commands via the (1) informationID or (2) ParentCategory parameter to index.php. NOTE: the vendor has disputed this issue in a comment on the researcher's blog, but research by CVE suggests that this might be a legitimate problem.    7.5  High  2017-07-18  2017-07-11  View
66989  CVE-2005-1243  Directory traversal vulnerability in the third party tool from SafeStone, as used to secure the iSeries AS/400 FTP server, allows remote attackers to access arbitrary files, including those from qsys.lib, via ".." sequences in a GET request.    Medium  2017-07-18  2017-07-10  View

Page 933 of 17672, showing 5 records out of 88360 total, starting on record 4661, ending on 4665

Actions