NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
81645 | CVE-2017-5545 | The main function in plistutil.c in libimobiledevice libplist through 1.12 allows attackers to obtain sensitive information from process memory or cause a denial of service (buffer over-read) via Apple Property List data that is too short. | 2 | 6.4 | Medium | 2017-02-07 | 2017-01-26 | View | |
81644 | CVE-2017-5544 | An issue was discovered on FiberHome Fengine S5800 switches V210R240. An unauthorized attacker can access the device's SSH service, using a password cracking tool to establish SSH connections quickly. This will trigger an increase in the SSH login timeout (each of the login attempts will occupy a connection slot for a longer time). Once this occurs, legitimate login attempts via SSH/telnet will be refused, resulting in a denial of service; you must restart the device. | 2 | 7.1 | High | 2017-02-07 | 2017-01-26 | View | |
81643 | CVE-2017-5543 | includes/classes/ia.core.users.php in Subrion CMS 4.0.5 allows remote attackers to conduct PHP Object Injection attacks via crafted serialized data in a salt cookie in a login request. | 2 | 7.5 | High | 2017-02-07 | 2017-01-26 | View | |
81642 | CVE-2017-5542 | Cross-site scripting (XSS) vulnerability in template/usererror.missing_extension.php in Symphony CMS before 2.6.10 allows remote attackers to inject arbitrary web script or HTML via the existing-folder parameter. | 2 | 4.3 | Medium | 2017-02-07 | 2017-01-26 | View | |
81641 | CVE-2017-5541 | Directory traversal vulnerability in template/usererror.missing_extension.php in Symphony CMS before 2.6.10 allows remote attackers to rename arbitrary files via a .. (dot dot) in the existing-folder and new-folder parameters. | 2 | 5 | Medium | 2017-02-07 | 2017-01-26 | View |
Page 1344 of 17672, showing 5 records out of 88360 total, starting on record 6716, ending on 6720