CVE List

Id CVE No. Status Description Phase Votes Comments Actions
102484  CVE-2017-5664  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170129)  None (candidate not yet proposed)    View
87681  CVE-2016-10173  Candidate  Directory traversal vulnerability in the minitar before 0.6 and archive-tar-minitar 0.5.2 gems for Ruby allows remote attackers to write to arbitrary files via a .. (dot dot) in a TAR archive entry.  Assigned (20170129)  None (candidate not yet proposed)    View
87682  CVE-2016-10174  Candidate  The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. This buffer overflow can be exploited by an unauthenticated attacker to achieve remote code execution.  Assigned (20170129)  None (candidate not yet proposed)    View
87683  CVE-2016-10175  Candidate  The NETGEAR WNR2000v5 router leaks its serial number when performing a request to the /BRS_netgear_success.html URI. This serial number allows a user to obtain the administrator username and password, when used in combination with the CVE-2016-10176 vulnerability that allows resetting the answers to the password-recovery questions.  Assigned (20170129)  None (candidate not yet proposed)    View
87684  CVE-2016-10176  Candidate  The NETGEAR WNR2000v5 router allows an administrator to perform sensitive actions by invoking the apply.cgi URL on the web server of the device. This special URL is handled by the embedded web server (uhttpd) and processed accordingly. The web server also contains another URL, apply_noauth.cgi, that allows an unauthenticated user to perform sensitive actions on the device. This functionality can be exploited to change the router settings (such as the answers to the password-recovery questions) and achieve remote code execution.  Assigned (20170129)  None (candidate not yet proposed)    View

Page 1084 of 20943, showing 5 records out of 104715 total, starting on record 5416, ending on 5420

Actions