Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2016-4885 | 1 Basercms | 1 Basercms | 2017-05-18 | 6.8 MEDIUM | 8.8 HIGH |
Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Feed version 3.0.10 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors. | |||||
CVE-2016-4886 | 1 Basercms | 1 Basercms | 2017-05-18 | 6.8 MEDIUM | 8.8 HIGH |
Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Mail version 3.0.10 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors. | |||||
CVE-2016-4883 | 1 Basercms | 1 Basercms | 2017-05-18 | 3.5 LOW | 5.4 MEDIUM |
Cross-site scripting vulnerability in baserCMS version 3.0.10 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |||||
CVE-2016-4887 | 1 Basercms | 1 Basercms | 2017-05-18 | 6.8 MEDIUM | 8.8 HIGH |
Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Uploader version 3.0.10 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors. | |||||
CVE-2017-8825 | 1 Libetpan Project | 1 Libetpan | 2017-05-18 | 5.0 MEDIUM | 7.5 HIGH |
A null dereference vulnerability has been found in the MIME handling component of LibEtPan before 1.8, as used in MailCore and MailCore 2. A crash can occur in low-level/imf/mailimf.c during a failed parse of a Cc header containing multiple e-mail addresses. | |||||
CVE-2016-4881 | 1 Basercms | 1 Basercms | 2017-05-18 | 6.8 MEDIUM | 8.8 HIGH |
Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Blog version 3.0.10 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors. | |||||
CVE-2016-4882 | 1 Basercms | 1 Basercms | 2017-05-18 | 6.8 MEDIUM | 8.8 HIGH |
Cross-site request forgery (CSRF) vulnerability in baserCMS version 3.0.10 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors. | |||||
CVE-2016-4878 | 1 Basercms | 1 Basercms | 2017-05-18 | 6.8 MEDIUM | 8.8 HIGH |
Cross-site request forgery (CSRF) vulnerability in baserCMS version 3.0.10 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors. | |||||
CVE-2016-4876 | 1 Basercms | 1 Basercms | 2017-05-18 | 6.8 MEDIUM | 8.8 HIGH |
Cross-site request forgery (CSRF) vulnerability in baserCMS version 3.0.10 and earlier allows remote attackers to hijack the authentication of administrators to execute arbitrary PHP code via unspecified vectors. | |||||
CVE-2017-0354 | 2 Microsoft, Nvidia | 2 Windows, Gpu Driver | 2017-05-17 | 4.7 MEDIUM | 4.7 MEDIUM |
All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer handler for DxgkDdiEscape where a call to certain function requiring lower IRQL can be made under raised IRQL which may lead to a denial of service. | |||||
CVE-2017-0353 | 1 Nvidia | 1 Gpu Driver | 2017-05-17 | 4.9 MEDIUM | 5.5 MEDIUM |
All versions of the NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer handler for DxgDdiEscape where due to improper locking on certain conditions may lead to a denial of service | |||||
CVE-2017-0347 | 2 Microsoft, Nvidia | 2 Windows, Gpu Driver | 2017-05-17 | 7.2 HIGH | 7.8 HIGH |
All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where a value passed from a user to the driver is not correctly validated and used as the index to an array, which may lead to denial of service or potential escalation of privileges. | |||||
CVE-2017-0348 | 2 Microsoft, Nvidia | 2 Windows, Gpu Driver | 2017-05-17 | 7.2 HIGH | 7.8 HIGH |
All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler where a NULL pointer dereference may lead to denial of service or potential escalation of privileges. | |||||
CVE-2017-0345 | 2 Microsoft, Nvidia | 2 Windows, Gpu Driver | 2017-05-17 | 7.2 HIGH | 7.8 HIGH |
All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where user provided input used as an array size is not correctly validated allows out of bound access in kernel memory and may lead to denial of service or potential escalation of privileges | |||||
CVE-2017-0343 | 2 Microsoft, Nvidia | 2 Windows, Gpu Driver | 2017-05-17 | 6.9 MEDIUM | 7.0 HIGH |
All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) where user can trigger a race condition due to lack of synchronization in two functions leading to a denial of service or potential escalation of privileges. | |||||
CVE-2017-0342 | 2 Microsoft, Nvidia | 2 Windows, Gpu Driver | 2017-05-17 | 7.2 HIGH | 7.8 HIGH |
All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler where incorrect calculation may cause an invalid address access leading to denial of service or potential escalation of privileges. | |||||
CVE-2017-0341 | 2 Microsoft, Nvidia | 2 Windows, Gpu Driver | 2017-05-17 | 7.2 HIGH | 7.8 HIGH |
All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where user provided input can trigger an access to a pointer that has not been initialized which may lead to denial of service or potential escalation of privileges. | |||||
CVE-2017-8892 | 1 Opentext | 1 Tempo Box | 2017-05-17 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting (XSS) vulnerability in OpenText Tempo Box 10.0.3 allows remote attackers to inject arbitrary web script or HTML persistently via the name of an uploaded image. | |||||
CVE-2017-8868 | 1 Flatcore | 1 Flatcore-cms | 2017-05-17 | 5.0 MEDIUM | 7.5 HIGH |
acp/core/files.browser.php in flatCore 1.4.7 allows file deletion via directory traversal in the delete parameter to acp/acp.php. The risk might be limited to requests submitted through CSRF. | |||||
CVE-2016-8916 | 1 Ibm | 1 Tivoli Storage Manager | 2017-05-17 | 2.1 LOW | 5.5 MEDIUM |
IBM Tivoli Storage Manager 5.5, 6.1-6.4, and 7.1 stores password information in a log file that could be read by a local user when a set password command is issued. IBM X-Force ID: 118472. |