CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
102692 | CVE-2017-5872 | Candidate | The TCP/IP networking module in Unisys ClearPath MCP systems with TCP-IP-SW 57.1 before 57.152, 58.1 before 58.142, or 59.1 before 59.172, when running a TLS 1.2 service, allows remote attackers to cause a denial of service (network connectivity disruption) via a client hello with a signature_algorithms extension above those defined in RFC 5246, which triggers a full memory dump. | Assigned (20170202) | None (candidate not yet proposed) | View | |
102693 | CVE-2017-5873 | Candidate | Unquoted Windows search path vulnerability in the guest service in Unisys s-Par before 4.4.20 allows local users to gain privileges via a Trojan horse executable file in the %SYSTEMDRIVE% directory, as demonstrated by program.exe. | Assigned (20170202) | None (candidate not yet proposed) | View | |
102694 | CVE-2017-5874 | Candidate | CSRF exists on D-Link DIR-600M Rev. Cx devices before v3.05ENB01_beta_20170306. This can be used to bypass authentication and insert XSS sequences or possibly have unspecified other impact. | Assigned (20170202) | None (candidate not yet proposed) | View | |
102695 | CVE-2017-5875 | Candidate | XSS was discovered in dotCMS 3.7.0, with an authenticated attack against the /myAccount addressID parameter. | Assigned (20170202) | None (candidate not yet proposed) | View | |
102696 | CVE-2017-5876 | Candidate | XSS was discovered in dotCMS 3.7.0, with an unauthenticated attack against the /news-events/events date parameter. | Assigned (20170202) | None (candidate not yet proposed) | View |
Page 1032 of 20943, showing 5 records out of 104715 total, starting on record 5156, ending on 5160