NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
87589 | CVE-2017-1000052 | Elixir Plug before v1.0.4, v1.1.7, v1.2.3 and v1.3.2 is vulnerable to null byte injection in the Plug.Static component, which may allow users to bypass filetype restrictions. | 2017-07-18 | 2017-07-17 | View | ||||
87845 | CVE-2017-11348 | In Octopus Deploy 3.x before 3.15.4, an authenticated user with PackagePush permission to upload packages could upload a maliciously crafted NuGet package, potentially overwriting other packages or modifying system files. This is a directory traversal in the PackageId value. | 2017-07-18 | 2017-07-17 | View | ||||
88101 | CVE-2017-7729 | On iSmartAlarm cube devices, there is Incorrect Access Control because a new key is transmitted in cleartext. | 2 | 5 | Medium | 2017-07-18 | 2017-07-13 | View | |
88357 | CVE-2016-9196 | A vulnerability in login authentication management in Cisco Aironet 1800, 2800, and 3800 Series Access Point platforms could allow an authenticated, local attacker to gain unrestricted root access to the underlying Linux operating system. The root Linux shell is provided for advanced troubleshooting and should not be available to individual users, even those with root privileges. The attacker must have the root password to exploit this vulnerability. More Information: CSCvb13893. Known Affected Releases: 8.2(121.0) 8.3(102.0). Known Fixed Releases: 8.4(1.53) 8.4(1.52) 8.3(111.0) 8.3(104.23) 8.2(130.0) 8.2(124.1). | 2 | 7.2 | High | 2017-07-18 | 2017-07-11 | View | |
66086 | CVE-2005-0323 | Cross-site scripting (XSS) vulnerability in Infinite Mobile Delivery Webmail 2.6 allows remote attackers to inject arbitrary web script or HTML via the URL. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View |
Page 15786 of 17672, showing 5 records out of 88360 total, starting on record 78926, ending on 78930