CVE List

Id CVE No. Status Description Phase Votes Comments Actions
102689  CVE-2017-5869  Candidate  Directory traversal vulnerability in the file import feature in Nuxeo Platform 6.0, 7.1, 7.2, and 7.3 allows remote authenticated users to upload and execute arbitrary JSP code via a .. (dot dot) in the X-File-Name header.  Assigned (20170202)  None (candidate not yet proposed)    View
102690  CVE-2017-5870  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170202)  None (candidate not yet proposed)    View
102691  CVE-2017-5871  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170202)  None (candidate not yet proposed)    View
102692  CVE-2017-5872  Candidate  The TCP/IP networking module in Unisys ClearPath MCP systems with TCP-IP-SW 57.1 before 57.152, 58.1 before 58.142, or 59.1 before 59.172, when running a TLS 1.2 service, allows remote attackers to cause a denial of service (network connectivity disruption) via a client hello with a signature_algorithms extension above those defined in RFC 5246, which triggers a full memory dump.  Assigned (20170202)  None (candidate not yet proposed)    View
102693  CVE-2017-5873  Candidate  Unquoted Windows search path vulnerability in the guest service in Unisys s-Par before 4.4.20 allows local users to gain privileges via a Trojan horse executable file in the %SYSTEMDRIVE% directory, as demonstrated by program.exe.  Assigned (20170202)  None (candidate not yet proposed)    View

Page 19914 of 20943, showing 5 records out of 104715 total, starting on record 99566, ending on 99570

Actions