NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
85423  CVE-2017-2152  WNC01WH firmware 1.0.0.9 and earlier allows authenticated attackers to execute arbitrary OS commands via unspecified vectors.    5.2  Medium  2017-05-07  2017-05-05  View
20399  CVE-2016-4962  The libxl device-handling in Xen 4.6.x and earlier allows local OS guest administrators to cause a denial of service (resource consumption or management facility confusion) or gain host OS privileges by manipulating information in guest controlled areas of xenstore.    6.8  Medium  2017-01-19  2016-11-28  View
85935  CVE-2017-5657  Several REST service endpoints of Apache Archiva are not protected against Cross Site Request Forgery (CSRF) attacks. A malicious site opened in the same browser as the archiva site, may send an HTML response that performs arbitrary actions on archiva services, with the same rights as the active archiva session (e.g. administrator rights).    Medium  2017-07-18  2017-07-07  View
20655  CVE-2016-5385  PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application"s outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, as demonstrated by (1) an application that makes a getenv("HTTP_PROXY") call or (2) a CGI configuration of PHP, aka an "httpoxy" issue.    5.1  Medium  2017-01-19  2016-11-28  View
86191  CVE-2017-9067  In MODX Revolution before 2.5.7, when PHP 5.3.3 is used, an attacker is able to include and execute arbitrary files on the web server due to insufficient validation of the action parameter to setup/index.php, aka directory traversal.    4.4  Medium  2017-06-03  2017-05-31  View

Page 14816 of 17672, showing 5 records out of 88360 total, starting on record 74076, ending on 74080

Actions