CVE List

Id CVE No. Status Description Phase Votes Comments Actions
103625  CVE-2017-6805  Candidate  Directory traversal vulnerability in the TFTP server in MobaXterm Personal Edition 9.4 allows remote attackers to read arbitrary files via a .. (dot dot) in a GET command.  Assigned (20170310)  None (candidate not yet proposed)    View
103624  CVE-2017-6804  Candidate  ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.  Assigned (20170310)  None (candidate not yet proposed)    View
103623  CVE-2017-6803  Candidate  Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface in the Scheduler in SolarWinds (formerly Serv-U) FTP Voyager 16.2.0 allow remote attackers to hijack the authentication of users for requests that (1) change the admin password, (2) terminate the scheduler, or (3) possibly execute arbitrary commands via crafted requests to Admin/XML/Result.xml.  Assigned (20170310)  None (candidate not yet proposed)    View
103622  CVE-2017-6802  Candidate  An issue was discovered in ytnef before 1.9.2. There is a potential heap-based buffer over-read on incoming Compressed RTF Streams, related to DecompressRTF() in libytnef.  Assigned (20170310)  None (candidate not yet proposed)    View
103621  CVE-2017-6801  Candidate  An issue was discovered in ytnef before 1.9.2. There is a potential out-of-bounds access with fields of Size 0 in TNEFParse() in libytnef.  Assigned (20170310)  None (candidate not yet proposed)    View

Page 219 of 20943, showing 5 records out of 104715 total, starting on record 1091, ending on 1095

Actions