NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
87751  CVE-2017-10974  Yaws 1.91 allows Unauthenticated Remote File Disclosure via HTTP Directory Traversal with /%5C../ to port 8080. NOTE: this CVE is only about use of an initial /%5C sequence to defeat traversal protection mechanisms; the initial /%5C sequence was apparently not discussed in earlier research on this product.    Medium  2017-07-18  2017-07-14  View
88007  CVE-2017-6017  A Resource Exhaustion issue was discovered in Schneider Electric Modicon M340 PLC BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP341000, BMXP342000, BMXP3420102, BMXP3420102CL, BMXP342020, BMXP342020H, BMXP342030, BMXP3420302, BMXP3420302H, and BMXP342030H. A remote attacker could send a specially crafted set of packets to the PLC causing it to freeze, requiring the operator to physically press the reset button on the PLC in order to recover.    7.8  High  2017-07-18  2017-07-05  View
88263  CVE-2017-9901  XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to Data from Faulting Address controls subsequent Write Address starting at Xfpx!gffGetFormatInfo+0x000000000002bfd5.    6.8  Medium  2017-07-18  2017-07-10  View
66248  CVE-2005-0491  Stack-based buffer overflow in Knox Arkeia Server Backup 5.3.x allows remote attackers to execute arbitrary code via a long type 77 request.    10  High  2017-07-18  2017-07-10  View
69320  CVE-2005-3682  Multiple SQL injection vulnerabilities in Wizz Forum 1.20 allow remote attackers to execute arbitrary SQL commands via (1) the AuthID parameter in ForumAuthDetails.php, and the TopicID parameter in (2) ForumTopicDetails.php and (3) ForumReply.php.    7.5  High  2017-07-18  2017-07-10  View

Page 1080 of 17672, showing 5 records out of 88360 total, starting on record 5396, ending on 5400

Actions