NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
83144  CVE-2017-2290  On Windows installations of the mcollective-puppet-agent plugin, version 1.12.0, a non-administrator user can create an executable that will be executed with administrator privileges on the next mco puppet run. Puppet Enterprise users are not affected. This is resolved in mcollective-puppet-agent 1.12.1.    High  2017-03-18  2017-03-13  View
82121  CVE-2016-9554  The Sophos Web Appliance Remote / Secure Web Gateway server (version 4.2.1.3) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface. These vulnerabilities occur in MgrDiagnosticTools.php (/controllers/MgrDiagnosticTools.php), in the component responsible for performing diagnostic tests with the UNIX wget utility. The application doesn"t properly escape the information passed in the "url" variable before calling the executeCommand class function ($this->dtObj->executeCommand). This function calls exec() with unsanitized user input allowing for remote command injection. The page that contains the vulnerabilities, /controllers/MgrDiagnosticTools.php, is accessed by a built-in command answered by the administrative interface. The command that calls to that vulnerable page (passed in the "section" parameter) is: "configuration". Exploitation of this vulnerability yields shell access to the remote machine under the "spiderman" user account.    High  2017-03-18  2017-03-13  View
83658  CVE-2015-2330  Late TLS certificate verification in WebKitGTK+ prior to 2.6.6 allows remote attackers to view a secure HTTP request, including, for example, secure cookies.    Medium  2017-03-18  2017-03-13  View
83148  CVE-2017-2785  An exploitable buffer overflow exists in the psnotifyd application of the Pharos PopUp printer client version 9.0. A specially crafted packet can be sent to the victim's computer and can lead to a heap based buffer overflow resulting in remote code execution. This client is always listening, has root privileges, and requires no user interaction to exploit.    10  High  2017-03-18  2017-03-13  View
83149  CVE-2017-2786  A denial of service vulnerability exists in the psnotifyd application of the Pharos PopUp printer client version 9.0. A specially crafted packet can be sent to the victim's computer and can lead to an out of bounds read causing a crash and a denial of service.    Medium  2017-03-18  2017-03-13  View

Page 15648 of 17672, showing 5 records out of 88360 total, starting on record 78236, ending on 78240

Actions