NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
86993 | CVE-2017-7884 | In Adam Kropelin adk0212 APC UPS Daemon through 3.14.14, the default installation of APCUPSD allows a local authenticated, but unprivileged, user to run arbitrary code with elevated privileges by replacing the service executable apcupsd.exe with a malicious executable that will run with SYSTEM privileges at startup. This occurs because of RW NT AUTHORITYAuthenticated Users permissions for %SYSTEMDRIVE%apcupsdinapcupsd.exe. | 2 | 7.2 | High | 2017-07-18 | 2017-07-06 | View | |
88019 | CVE-2017-6042 | A Cross-Site Request Forgery issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versions prior to 4.0.11. Affected devices do not verify if a request was intentionally sent by the logged-in user, which may allow an attacker to trick a client into making an unintentional request to the web server that will be treated as an authentic request. | 2 | 6.8 | Medium | 2017-07-18 | 2017-07-06 | View | |
88020 | CVE-2017-6044 | An Improper Authorization issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versions prior to 4.0.11. Several files and directories can be accessed without authentication, which may allow a remote attacker to perform sensitive functions including arbitrary file upload, file download, and device reboot. | 2 | 10 | High | 2017-07-18 | 2017-07-06 | View | |
88021 | CVE-2017-6046 | An Insufficiently Protected Credentials issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versions prior to 4.0.11. Sensitive information is insufficiently protected during transmission and vulnerable to sniffing, which could lead to information disclosure. | 2 | 5 | Medium | 2017-07-18 | 2017-07-06 | View | |
87011 | CVE-2017-8461 | Windows RPC with Routing and Remote Access enabled in Windows XP and Windows Server 2003 allows an attacker to execute code on a targeted RPC server which has Routing and Remote Access enabled via a specially crafted application, aka Windows RPC Remote Code Execution Vulnerability. | 2 | 6.9 | Medium | 2017-07-18 | 2017-07-06 | View |
Page 1301 of 17672, showing 5 records out of 88360 total, starting on record 6501, ending on 6505