NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
86431 | CVE-2016-10372 | The Eir D1000 modem does not properly restrict the TR-064 protocol, which allows remote attackers to execute arbitrary commands via TCP port 7547, as demonstrated by opening WAN access to TCP port 80, retrieving the login password (which defaults to the Wi-Fi password), and using the NewNTPServer feature. | 2 | 10 | High | 2017-05-27 | 2017-05-25 | View | |
86687 | CVE-2017-9441 | ** DISPUTED ** Multiple cross-site scripting (XSS) vulnerabilities in BigTree CMS through 4.2.18 allow remote authenticated users to inject arbitrary web script or HTML by uploading a crafted package, triggering mishandling of the (1) title or (2) version or (3) author_name parameter in manifest.json. This issue exists in coreadminmodulesdeveloperextensionsinstallunpack.php and coreadminmodulesdeveloperpackagesinstallunpack.php. NOTE: the vendor states You must implicitly trust any package or extension you install as they all have the ability to write PHP files. | 2 | 3.5 | Low | 2017-06-17 | 2017-06-12 | View | |
86943 | CVE-2017-5244 | Routes used to stop running Metasploit tasks (either particular ones or all tasks) allowed GET requests. Only POST requests should have been allowed, as the stop/stop_all routes change the state of the service. This could have allowed an attacker to stop currently-running Metasploit tasks by getting an authenticated user to execute JavaScript. As of Metasploit 4.14.0 (Update 2017061301), the routes for stopping tasks only allow POST requests, which validate the presence of a secret token to prevent CSRF attacks. | 2 | 3.5 | Low | 2017-07-18 | 2017-07-05 | View | |
87199 | CVE-2016-10334 | In all Android releases from CAF using the Linux kernel, a dynamically-protected DDR region could potentially get overwritten. | 2 | 4.3 | Medium | 2017-06-23 | 2017-06-19 | View | |
87455 | CVE-2015-1870 | The event scripts in Automatic Bug Reporting Tool (ABRT) uses world-readable permission on a copy of sosreport file in problem directories, which allows local users to obtain sensitive information from /var/log/messages via unspecified vectors. | 2017-06-28 | 2017-06-27 | View |
Page 1457 of 17672, showing 5 records out of 88360 total, starting on record 7281, ending on 7285