CVE List

Id CVE No. Status Description Phase Votes Comments Actions
103010  CVE-2017-6190  Candidate  Directory traversal vulnerability in the web interface on the D-Link DWR-116 device with firmware before V1.05b09 allows remote attackers to read arbitrary files via a .. (dot dot) in a "GET /uir/" request.  Assigned (20170222)  None (candidate not yet proposed)    View
103009  CVE-2017-6189  Candidate  Untrusted search path vulnerability in Amazon Kindle for PC before 1.19 allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse DLL in the current working directory of the Kindle Setup installer.  Assigned (20170222)  None (candidate not yet proposed)    View
103008  CVE-2017-6188  Candidate  Munin before 2.999.6 has a local file write vulnerability when CGI graphs are enabled. Setting multiple upper_limit GET parameters allows overwriting any file accessible to the www-data user.  Assigned (20170222)  None (candidate not yet proposed)    View
103007  CVE-2017-6187  Candidate  Buffer overflow in the built-in web server in DiskSavvy Enterprise 9.4.18 allows remote attackers to execute arbitrary code via a long URI in a GET request.  Assigned (20170222)  None (candidate not yet proposed)    View
103006  CVE-2017-6186  Candidate  Code injection vulnerability in Bitdefender Total Security 12.0 (and earlier), Internet Security 12.0 (and earlier), and Antivirus Plus 12.0 (and earlier) allows a local attacker to bypass a self-protection mechanism, inject arbitrary code, and take full control of any Bitdefender process via a "DoubleAgent" attack. One perspective on this issue is that (1) these products do not use the Protected Processes feature, and therefore an attacker can enter an arbitrary Application Verifier Provider DLL under Image File Execution Options in the registry; (2) the self-protection mechanism is intended to block all local processes (regardless of privileges) from modifying Image File Execution Options for these products; and (3) this mechanism can be bypassed by an attacker who temporarily renames Image File Execution Options during the attack.  Assigned (20170222)  None (candidate not yet proposed)    View

Page 342 of 20943, showing 5 records out of 104715 total, starting on record 1706, ending on 1710

Actions