NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
87724 | CVE-2017-10911 | The make_response function in drivers/block/xen-blkback/blkback.c in the Linux kernel before 4.11.8 allows guest OS users to obtain sensitive information from host OS (or other guest OS) kernel memory by leveraging the copying of uninitialized padding fields in Xen block-interface response structures, aka XSA-216. | 2 | 4.9 | Medium | 2017-07-18 | 2017-07-14 | View | |
87980 | CVE-2017-3103 | Adobe Connect versions 9.6.1 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to a stored cross-site scripting attack. | 2017-07-18 | 2017-07-17 | View | ||||
88236 | CVE-2017-9874 | IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to a User Mode Write AV starting at FPX!FPX_GetScanDevicePropertyGroup+0x0000000000007822. | 2 | 6.8 | Medium | 2017-07-18 | 2017-07-11 | View | |
59820 | CVE-2006-1098 | ** DISPUTED ** Multiple SQL injection vulnerabilities in NZ Ecommerce allow remote attackers to execute arbitrary SQL commands via the (1) informationID or (2) ParentCategory parameter to index.php. NOTE: the vendor has disputed this issue in a comment on the researcher's blog, but research by CVE suggests that this might be a legitimate problem. | 2 | 7.5 | High | 2017-07-18 | 2017-07-11 | View | |
66989 | CVE-2005-1243 | Directory traversal vulnerability in the third party tool from SafeStone, as used to secure the iSeries AS/400 FTP server, allows remote attackers to access arbitrary files, including those from qsys.lib, via ".." sequences in a GET request. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View |
Page 933 of 17672, showing 5 records out of 88360 total, starting on record 4661, ending on 4665