NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
86993  CVE-2017-7884  In Adam Kropelin adk0212 APC UPS Daemon through 3.14.14, the default installation of APCUPSD allows a local authenticated, but unprivileged, user to run arbitrary code with elevated privileges by replacing the service executable apcupsd.exe with a malicious executable that will run with SYSTEM privileges at startup. This occurs because of RW NT AUTHORITYAuthenticated Users permissions for %SYSTEMDRIVE%apcupsdinapcupsd.exe.    7.2  High  2017-07-18  2017-07-06  View
88019  CVE-2017-6042  A Cross-Site Request Forgery issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versions prior to 4.0.11. Affected devices do not verify if a request was intentionally sent by the logged-in user, which may allow an attacker to trick a client into making an unintentional request to the web server that will be treated as an authentic request.    6.8  Medium  2017-07-18  2017-07-06  View
88020  CVE-2017-6044  An Improper Authorization issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versions prior to 4.0.11. Several files and directories can be accessed without authentication, which may allow a remote attacker to perform sensitive functions including arbitrary file upload, file download, and device reboot.    10  High  2017-07-18  2017-07-06  View
88021  CVE-2017-6046  An Insufficiently Protected Credentials issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versions prior to 4.0.11. Sensitive information is insufficiently protected during transmission and vulnerable to sniffing, which could lead to information disclosure.    Medium  2017-07-18  2017-07-06  View
87011  CVE-2017-8461  Windows RPC with Routing and Remote Access enabled in Windows XP and Windows Server 2003 allows an attacker to execute code on a targeted RPC server which has Routing and Remote Access enabled via a specially crafted application, aka Windows RPC Remote Code Execution Vulnerability.    6.9  Medium  2017-07-18  2017-07-06  View

Page 1301 of 17672, showing 5 records out of 88360 total, starting on record 6501, ending on 6505

Actions