CVE List

Id CVE No. Status Description Phase Votes Comments Actions
102050  CVE-2017-5230  Candidate  The Java keystore in all versions and editions of Rapid7 Nexpose is encrypted with a static password of "r@p1d7k3y5t0r3" which is not modifiable by the user. The keystore provides storage for saved scan credentials in an otherwise secure location on disk.  Assigned (20170109)  None (candidate not yet proposed)    View
102049  CVE-2017-5229  Candidate  All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter extapi Clipboard.parse_dump() function. By using a specially-crafted build of Meterpreter, it is possible to write to an arbitrary directory on the Metasploit console with the permissions of the running Metasploit instance.  Assigned (20170109)  None (candidate not yet proposed)    View
102048  CVE-2017-5228  Candidate  All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter stdapi Dir.download() function. By using a specially-crafted build of Meterpreter, it is possible to write to an arbitrary directory on the Metasploit console with the permissions of the running Metasploit instance.  Assigned (20170109)  None (candidate not yet proposed)    View
102047  CVE-2017-5227  Candidate  QNAP QTS before 4.2.4 Build 20170313 allows local users to obtain sensitive Domain Administrator password information by reading data in an XOR format within the /etc/config/uLinux.conf configuration file.  Assigned (20170109)  None (candidate not yet proposed)    View
102046  CVE-2017-5226  Candidate  When executing a program via the bubblewrap sandbox, the nonpriv session can escape to the parent session by using the TIOCSTI ioctl to push characters into the terminal"s input buffer, allowing an attacker to escape the sandbox.  Assigned (20170109)  None (candidate not yet proposed)    View

Page 534 of 20943, showing 5 records out of 104715 total, starting on record 2666, ending on 2670

Actions