CVE List

Id CVE No. Status Description Phase Votes Comments Actions
102164  CVE-2017-5344  Candidate  An issue was discovered in dotCMS through 3.6.1. The findChildrenByFilter() function which is called by the web accessible path /categoriesServlet performs string interpolation and direct SQL query execution. SQL quote escaping and a keyword blacklist were implemented in a new class, SQLUtil (main/java/com/dotmarketing/common/util/SQLUtil.java), as part of the remediation of CVE-2016-8902; however, these can be overcome in the case of the q and inode parameters to the /categoriesServlet path. Overcoming these controls permits a number of blind boolean SQL injection vectors in either parameter. The /categoriesServlet web path can be accessed remotely and without authentication in a default dotCMS deployment.  Assigned (20170111)  None (candidate not yet proposed)    View
36884  CVE-2008-6767  Candidate  wp-admin/upgrade.php in WordPress, probably 2.6.x, allows remote attackers to upgrade the application, and possibly cause a denial of service (application outage), via a direct request.  Assigned (20090428)  None (candidate not yet proposed)    View
102420  CVE-2017-5600  Candidate  The Data Warehouse component in NetApp OnCommand Insight before 7.2.3 allows remote attackers to obtain administrative access by leveraging a default privileged account.  Assigned (20170127)  None (candidate not yet proposed)    View
37140  CVE-2008-7023  Candidate  Aruba Mobility Controller running ArubaOS 3.3.1.16, and possibly other versions, installs the same default X.509 certificate for all installations, which allows remote attackers to bypass authentication. NOTE: this is only a vulnerability when the administrator does not follow recommendations in the product"s security documentation.  Assigned (20090821)  None (candidate not yet proposed)    View
102676  CVE-2017-5856  Candidate  Memory leak in the megasas_handle_dcmd function in hw/scsi/megasas.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption) via MegaRAID Firmware Interface (MFI) commands with the sglist size set to a value over 2 Gb.  Assigned (20170201)  None (candidate not yet proposed)    View

Page 1668 of 20943, showing 5 records out of 104715 total, starting on record 8336, ending on 8340

Actions