NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
83748  CVE-2017-5899  Directory traversal vulnerability in the setuid root helper binary in S-nail (later S-mailx) before 14.8.16 allows local users to write to arbitrary files and consequently gain root privileges via a .. (dot dot) in the randstr argument.    6.9  Medium  2017-04-27  2017-03-31  View
83751  CVE-2017-5932  The path autocompletion feature in Bash 4.4 allows local users to gain privileges via a crafted filename starting with a (double quote) character and a command substitution metacharacter.    4.6  Medium  2017-04-27  2017-03-31  View
83499  CVE-2017-6954  An issue was discovered in includes/component.php in the BuddyPress Docs plugin before 1.9.3 for WordPress. It is possible for authenticated users to edit documents of other users without proper permissions.    Medium  2017-04-27  2017-03-31  View
84798  CVE-2017-7320  setup/controllers/language.php in MODX Revolution 2.5.4-pl and earlier does not properly constrain the language parameter, which allows remote attackers to conduct Cookie-Bombing attacks and cause a denial of service (cookie quota exhaustion), or conduct HTTP Response Splitting attacks with resultant XSS, via an invalid parameter value.    4.3  Medium  2017-04-27  2017-03-31  View
84799  CVE-2017-7321  setup/controllers/welcome.php in MODX Revolution 2.5.4-pl and earlier allows remote attackers to execute arbitrary PHP code via the config_key parameter to the setup/index.php?action=welcome URI.    7.5  High  2017-04-27  2017-03-31  View

Page 15805 of 17672, showing 5 records out of 88360 total, starting on record 79021, ending on 79025

Actions