NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
83355 | CVE-2017-6445 | The auto-update feature of Open Embedded Linux Entertainment Center (OpenELEC) 6.0.3, 7.0.1, and 8.0.4 uses neither encrypted connections nor signed updates. A man-in-the-middle attacker could manipulate the update packages to gain root access remotely. | 2 | 7.6 | High | 2017-06-28 | 2017-06-25 | View | |
83354 | CVE-2017-6444 | The MikroTik Router hAP Lite 6.25 has no protection mechanism for unsolicited TCP ACK packets in the case of a fast network connection, which allows remote attackers to cause a denial of service (CPU consumption) by sending many ACK packets. After the attacker stops the exploit, the CPU usage is 100% and the router requires a reboot for normal operation. | 2 | 7.8 | High | 2017-03-18 | 2017-03-14 | View | |
83353 | CVE-2017-6443 | Cross-site scripting (XSS) vulnerability in EPSON TMNet WebConfig 1.00 allows remote attackers to inject arbitrary web script or HTML via the W_AD1 parameter to Forms/oadmin_1. | 2 | 4.3 | Medium | 2017-03-18 | 2017-03-16 | View | |
83352 | CVE-2017-6440 | The parse_data_node function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (memory allocation error) via a crafted plist file. | 2 | 1.9 | Low | 2017-04-27 | 2017-04-13 | View | |
83351 | CVE-2017-6439 | Heap-based buffer overflow in the parse_string_node function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (out-of-bounds write) via a crafted plist file. | 2 | 1.9 | Low | 2017-04-27 | 2017-04-03 | View |
Page 1002 of 17672, showing 5 records out of 88360 total, starting on record 5006, ending on 5010