NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
87751 | CVE-2017-10974 | Yaws 1.91 allows Unauthenticated Remote File Disclosure via HTTP Directory Traversal with /%5C../ to port 8080. NOTE: this CVE is only about use of an initial /%5C sequence to defeat traversal protection mechanisms; the initial /%5C sequence was apparently not discussed in earlier research on this product. | 2 | 5 | Medium | 2017-07-18 | 2017-07-14 | View | |
88007 | CVE-2017-6017 | A Resource Exhaustion issue was discovered in Schneider Electric Modicon M340 PLC BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP341000, BMXP342000, BMXP3420102, BMXP3420102CL, BMXP342020, BMXP342020H, BMXP342030, BMXP3420302, BMXP3420302H, and BMXP342030H. A remote attacker could send a specially crafted set of packets to the PLC causing it to freeze, requiring the operator to physically press the reset button on the PLC in order to recover. | 2 | 7.8 | High | 2017-07-18 | 2017-07-05 | View | |
88263 | CVE-2017-9901 | XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to Data from Faulting Address controls subsequent Write Address starting at Xfpx!gffGetFormatInfo+0x000000000002bfd5. | 2 | 6.8 | Medium | 2017-07-18 | 2017-07-10 | View | |
66248 | CVE-2005-0491 | Stack-based buffer overflow in Knox Arkeia Server Backup 5.3.x allows remote attackers to execute arbitrary code via a long type 77 request. | 2 | 10 | High | 2017-07-18 | 2017-07-10 | View | |
69320 | CVE-2005-3682 | Multiple SQL injection vulnerabilities in Wizz Forum 1.20 allow remote attackers to execute arbitrary SQL commands via (1) the AuthID parameter in ForumAuthDetails.php, and the TopicID parameter in (2) ForumTopicDetails.php and (3) ForumReply.php. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View |
Page 1080 of 17672, showing 5 records out of 88360 total, starting on record 5396, ending on 5400