CVE List

Id CVE No. Status Description Phase Votes Comments Actions
104138  CVE-2017-7318  Candidate  Siklu EtherHaul devices before 7.4.0 are vulnerable to a remote command execution (RCE) vulnerability. This vulnerability allows a remote attacker to execute commands and retrieve information such as usernames and plaintext passwords from the device with no authentication.  Assigned (20170329)  None (candidate not yet proposed)    View
104139  CVE-2017-7319  Candidate  ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.  Assigned (20170329)  None (candidate not yet proposed)    View
87832  CVE-2016-10310  Candidate  Buffer overflow in the MobiLink Synchronization Server component in SAP SQL Anywhere 17 and possibly earlier allows remote authenticated users to cause a denial of service (resource consumption and process crash) by sending a crafted packet several times, aka SAP Security Note 2308778.  Assigned (20170330)  None (candidate not yet proposed)    View
87833  CVE-2016-10311  Candidate  Stack-based buffer overflow in SAP NetWeaver 7.0 through 7.5 allows remote attackers to cause a denial of service () by sending a crafted packet to the SAPSTARTSRV port, aka SAP Security Note 2295238.  Assigned (20170330)  None (candidate not yet proposed)    View
104140  CVE-2017-7320  Candidate  setup/controllers/language.php in MODX Revolution 2.5.4-pl and earlier does not properly constrain the language parameter, which allows remote attackers to conduct Cookie-Bombing attacks and cause a denial of service (cookie quota exhaustion), or conduct HTTP Response Splitting attacks with resultant XSS, via an invalid parameter value.  Assigned (20170330)  None (candidate not yet proposed)    View

Page 20243 of 20943, showing 5 records out of 104715 total, starting on record 101211, ending on 101215

Actions