CVE List

Id CVE No. Status Description Phase Votes Comments Actions
101998  CVE-2017-5178  Candidate  An issue was discovered in Schneider Electric Tableau Server/Desktop Versions 7.0 to 10.1.3 in Wonderware Intelligence Versions 2014R3 and prior. These versions contain a system account that is installed by default. The default system account is difficult to configure with non-default credentials after installation, and changing the default credentials in the embedded Tableau Server is not documented. If Tableau Server is used with Windows integrated security (Active Directory), the software is not vulnerable. However, when Tableau Server is used with local authentication mode, the software is vulnerable. The default system account could be used to gain unauthorized access.  Assigned (20170103)  None (candidate not yet proposed)    View
101999  CVE-2017-5179  Candidate  Cross-site scripting (XSS) vulnerability in Tenable Nessus before 6.9.3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20170103)  None (candidate not yet proposed)    View
87617  CVE-2016-10115  Candidate  NETGEAR Arlo base stations with firmware 1.7.5_6178 and earlier, Arlo Q devices with firmware 1.8.0_5551 and earlier, and Arlo Q Plus devices with firmware 1.8.1_6094 and earlier have a default password of 12345678, which makes it easier for remote attackers to obtain access after a factory reset or in a factory configuration.  Assigned (20170104)  None (candidate not yet proposed)    View
87618  CVE-2016-10116  Candidate  NETGEAR Arlo base stations with firmware 1.7.5_6178 and earlier, Arlo Q devices with firmware 1.8.0_5551 and earlier, and Arlo Q Plus devices with firmware 1.8.1_6094 and earlier use a pattern of adjective, noun, and three-digit number for the customized password, which makes it easier for remote attackers to obtain access via a dictionary attack.  Assigned (20170104)  None (candidate not yet proposed)    View
102000  CVE-2017-5180  Candidate  Firejail before 0.9.44.4 and 0.9.38.x LTS before 0.9.38.8 LTS does not consider the .Xauthority case during its attempt to prevent accessing user files with an euid of zero, which allows local users to conduct sandbox-escape attacks via vectors involving a symlink and the --private option.  Assigned (20170104)  None (candidate not yet proposed)    View

Page 19758 of 20943, showing 5 records out of 104715 total, starting on record 98786, ending on 98790

Actions