NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
83355  CVE-2017-6445  The auto-update feature of Open Embedded Linux Entertainment Center (OpenELEC) 6.0.3, 7.0.1, and 8.0.4 uses neither encrypted connections nor signed updates. A man-in-the-middle attacker could manipulate the update packages to gain root access remotely.    7.6  High  2017-06-28  2017-06-25  View
83354  CVE-2017-6444  The MikroTik Router hAP Lite 6.25 has no protection mechanism for unsolicited TCP ACK packets in the case of a fast network connection, which allows remote attackers to cause a denial of service (CPU consumption) by sending many ACK packets. After the attacker stops the exploit, the CPU usage is 100% and the router requires a reboot for normal operation.    7.8  High  2017-03-18  2017-03-14  View
83353  CVE-2017-6443  Cross-site scripting (XSS) vulnerability in EPSON TMNet WebConfig 1.00 allows remote attackers to inject arbitrary web script or HTML via the W_AD1 parameter to Forms/oadmin_1.    4.3  Medium  2017-03-18  2017-03-16  View
83352  CVE-2017-6440  The parse_data_node function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (memory allocation error) via a crafted plist file.    1.9  Low  2017-04-27  2017-04-13  View
83351  CVE-2017-6439  Heap-based buffer overflow in the parse_string_node function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (out-of-bounds write) via a crafted plist file.    1.9  Low  2017-04-27  2017-04-03  View

Page 1002 of 17672, showing 5 records out of 88360 total, starting on record 5006, ending on 5010

Actions