NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
87946  CVE-2017-2298  The mcollective-sshkey-security plugin before 0.5.1 for Puppet uses a server-specified identifier as part of a path where a file is written. A compromised server could use this to write a file to an arbitrary location on the client with the filename appended with the string _pub.pem.    4.3  Medium  2017-07-18  2017-07-06  View
87483  CVE-2017-5241  Biscom Secure File Transfer version 5.1.1015 (and possibly prior) is vulnerable to post-authentication persistent cross-site scripting (XSS) in the Name and Description fields of a Workspace, as well as the Description field of a File Details pane of a file stored in a Workspace. This issue has been resolved in version 5.1.1025.    3.5  Low  2017-07-18  2017-07-06  View
87228  CVE-2017-0897  ExpressionEngine version 2.x < 2.11.8 and version 3.x < 3.5.5 create an object signing token with weak entropy. Successfully guessing the token can lead to remote code execution.    Medium  2017-07-18  2017-07-06  View
87484  CVE-2017-7686  Apache Ignite 1.0.0-RC3 to 2.0 uses an update notifier component to update the users about new project releases that include additional functionality, bug fixes and performance improvements. To do that the component communicates to an external PHP server (http://ignite.run) where it needs to send some system properties like Apache Ignite or Java version. Some of the properties might contain user sensitive information.    Medium  2017-07-18  2017-07-06  View
87229  CVE-2017-1000364  An issue was discovered in the size of the stack guard page on Linux, specifically a 4k stack guard page is not sufficiently large and can be jumped over (the stack guard page is bypassed), this affects Linux Kernel versions 4.11.5 and earlier (the stackguard page was introduced in 2010).    6.2  Medium  2017-07-18  2017-07-06  View

Page 1299 of 17672, showing 5 records out of 88360 total, starting on record 6491, ending on 6495

Actions