CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
104130 | CVE-2017-7310 | Candidate | A buffer overflow vulnerability in Import Command in Sync Breeze Enterprise Client 9.5.16, Disk Sorter Enterprise Client 9.5.12, and DiskBoss Enterprise Client 7.8.16 allows attackers to execute arbitrary code via a crafted XML file containing a long name attribute of a classify element. | Assigned (20170329) | None (candidate not yet proposed) | View | |
104129 | CVE-2017-7309 | Candidate | A cross-site scripting (XSS) vulnerability in the MantisBT Configuration Report page (adm_config_report.php) allows remote attackers to inject arbitrary code (if CSP settings permit it) through a crafted "config_option" parameter. This is fixed in 1.3.9, 2.1.3, and 2.2.3. | Assigned (20170329) | None (candidate not yet proposed) | View | |
104128 | CVE-2017-7308 | Candidate | The packet_set_ring function in net/packet/af_packet.c in the Linux kernel through 4.10.6 does not properly validate certain block-size data, which allows local users to cause a denial of service (overflow) or possibly have unspecified other impact via crafted system calls. | Assigned (20170329) | None (candidate not yet proposed) | View | |
104127 | CVE-2017-7307 | Candidate | Riverbed RiOS before 9.0.1 does not properly restrict shell access in single-user mode, which makes it easier for physically proximate attackers to obtain root privileges and access decrypted data by replacing the /opt/tms/bin/cli file. | Assigned (20170329) | None (candidate not yet proposed) | View | |
104126 | CVE-2017-7306 | Candidate | ** DISPUTED ** Riverbed RiOS through 9.6.0 has a weak default password for the secure vault, which makes it easier for physically proximate attackers to defeat the secure-vault protection mechanism by leveraging knowledge of the password algorithm and the appliance serial number. NOTE: the vendor believes that this does not meet the definition of a vulnerability. The product contains correct computational logic for supporting arbitrary password changes by customers; however, a password change is optional to meet different customers" needs. | Assigned (20170329) | None (candidate not yet proposed) | View |
Page 118 of 20943, showing 5 records out of 104715 total, starting on record 586, ending on 590