NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
85941  CVE-2017-5965  The package manager in Sitecore CRM 8.1 Rev 151207 allows remote authenticated administrators to execute arbitrary ASP code by creating a ZIP archive in which a .asp file has a .. in its pathname, visiting sitecore/shell/applications/install/dialogs/Upload%20Package/UploadPackage2.aspx to upload this archive and extract its contents, and visiting a URI under sitecore/ to execute the .asp file.    6.5  Medium  2017-06-12  2017-06-08  View
20661  CVE-2016-5392  The API server in Kubernetes, as used in Red Hat OpenShift Enterprise 3.2, in a multi tenant environment allows remote authenticated users with knowledge of other project names to obtain sensitive project and user information via vectors related to the watch-cache list.    6.8  Medium  2017-01-19  2016-08-05  View
20917  CVE-2016-5715  Open redirect vulnerability in the Console in Puppet Enterprise 2015.x and 2016.x before 2016.4.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a // (slash slash) followed by a domain in the redirect parameter. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-6501.    5.8  Medium  2017-01-19  2017-01-17  View
21173  CVE-2016-6398  The PPTP server in Cisco IOS 15.5(3)M does not properly initialize packet buffers, which allows remote attackers to obtain sensitive information from earlier network communication by reading packet data, aka Bug ID CSCvb16274.    Medium  2017-01-19  2016-11-28  View
86709  CVE-2017-9517  atmail before 7.8.0.2 has CSRF, allowing an attacker to upload and import users via CSV.    6.8  Medium  2017-06-17  2017-06-13  View

Page 15034 of 17672, showing 5 records out of 88360 total, starting on record 75166, ending on 75170

Actions