CVE List

Id CVE No. Status Description Phase Votes Comments Actions
104105  CVE-2017-7285  Candidate  A vulnerability in the network stack of MikroTik Version 6.38.5 released 2017-03-09 could allow an unauthenticated remote attacker to exhaust all available CPU via a flood of TCP RST packets, preventing the affected router from accepting new TCP connections.  Assigned (20170327)  None (candidate not yet proposed)    View
104104  CVE-2017-7284  Candidate  An attacker that has hijacked a Unitrends Enterprise Backup (before 9.1.2) web server session can leverage api/includes/users.php to change the password of the logged in account without knowing the current password. This allows for an account takeover.  Assigned (20170327)  None (candidate not yet proposed)    View
104103  CVE-2017-7283  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170327)  None (candidate not yet proposed)    View
104102  CVE-2017-7282  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170327)  None (candidate not yet proposed)    View
104101  CVE-2017-7281  Candidate  An issue was discovered in Unitrends Enterprise Backup before 9.1.2. A lack of sanitization of user input in the createReportName and saveReport functions in recoveryconsole/bpl/reports.php allows for an authenticated user to create a randomly named file on disk with a user-controlled extension, contents, and path, leading to remote code execution, aka Unrestricted File Upload.  Assigned (20170327)  None (candidate not yet proposed)    View

Page 123 of 20943, showing 5 records out of 104715 total, starting on record 611, ending on 615

Actions