CVE List

Id CVE No. Status Description Phase Votes Comments Actions
104100  CVE-2017-7280  Candidate  An issue was discovered in api/includes/systems.php in Unitrends Enterprise Backup before 9.0.0. User input is not properly filtered before being sent to a popen function. This allows for remote code execution by sending a specially crafted user variable.  Assigned (20170327)  None (candidate not yet proposed)    View
104099  CVE-2017-7279  Candidate  An unprivileged user of the Unitrends Enterprise Backup before 9.0.0 web server can escalate to root privileges by modifying the "token" cookie issued at login.  Assigned (20170327)  None (candidate not yet proposed)    View
104098  CVE-2017-7278  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170327)  None (candidate not yet proposed)    View
104097  CVE-2017-7277  Candidate  The TCP stack in the Linux kernel through 4.10.6 mishandles the SCM_TIMESTAMPING_OPT_STATS feature, which allows local users to obtain sensitive information from the kernel"s internal socket data structures or cause a denial of service (out-of-bounds read) via crafted system calls, related to net/core/skbuff.c and net/socket.c.  Assigned (20170327)  None (candidate not yet proposed)    View
104096  CVE-2017-7276  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170327)  None (candidate not yet proposed)    View

Page 124 of 20943, showing 5 records out of 104715 total, starting on record 616, ending on 620

Actions