CVE List

Id CVE No. Status Description Phase Votes Comments Actions
102692  CVE-2017-5872  Candidate  The TCP/IP networking module in Unisys ClearPath MCP systems with TCP-IP-SW 57.1 before 57.152, 58.1 before 58.142, or 59.1 before 59.172, when running a TLS 1.2 service, allows remote attackers to cause a denial of service (network connectivity disruption) via a client hello with a signature_algorithms extension above those defined in RFC 5246, which triggers a full memory dump.  Assigned (20170202)  None (candidate not yet proposed)    View
102693  CVE-2017-5873  Candidate  Unquoted Windows search path vulnerability in the guest service in Unisys s-Par before 4.4.20 allows local users to gain privileges via a Trojan horse executable file in the %SYSTEMDRIVE% directory, as demonstrated by program.exe.  Assigned (20170202)  None (candidate not yet proposed)    View
102694  CVE-2017-5874  Candidate  CSRF exists on D-Link DIR-600M Rev. Cx devices before v3.05ENB01_beta_20170306. This can be used to bypass authentication and insert XSS sequences or possibly have unspecified other impact.  Assigned (20170202)  None (candidate not yet proposed)    View
102695  CVE-2017-5875  Candidate  XSS was discovered in dotCMS 3.7.0, with an authenticated attack against the /myAccount addressID parameter.  Assigned (20170202)  None (candidate not yet proposed)    View
102696  CVE-2017-5876  Candidate  XSS was discovered in dotCMS 3.7.0, with an unauthenticated attack against the /news-events/events date parameter.  Assigned (20170202)  None (candidate not yet proposed)    View

Page 1032 of 20943, showing 5 records out of 104715 total, starting on record 5156, ending on 5160

Actions