NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
83748 | CVE-2017-5899 | Directory traversal vulnerability in the setuid root helper binary in S-nail (later S-mailx) before 14.8.16 allows local users to write to arbitrary files and consequently gain root privileges via a .. (dot dot) in the randstr argument. | 2 | 6.9 | Medium | 2017-04-27 | 2017-03-31 | View | |
83751 | CVE-2017-5932 | The path autocompletion feature in Bash 4.4 allows local users to gain privileges via a crafted filename starting with a (double quote) character and a command substitution metacharacter. | 2 | 4.6 | Medium | 2017-04-27 | 2017-03-31 | View | |
83499 | CVE-2017-6954 | An issue was discovered in includes/component.php in the BuddyPress Docs plugin before 1.9.3 for WordPress. It is possible for authenticated users to edit documents of other users without proper permissions. | 2 | 4 | Medium | 2017-04-27 | 2017-03-31 | View | |
84798 | CVE-2017-7320 | setup/controllers/language.php in MODX Revolution 2.5.4-pl and earlier does not properly constrain the language parameter, which allows remote attackers to conduct Cookie-Bombing attacks and cause a denial of service (cookie quota exhaustion), or conduct HTTP Response Splitting attacks with resultant XSS, via an invalid parameter value. | 2 | 4.3 | Medium | 2017-04-27 | 2017-03-31 | View | |
84799 | CVE-2017-7321 | setup/controllers/welcome.php in MODX Revolution 2.5.4-pl and earlier allows remote attackers to execute arbitrary PHP code via the config_key parameter to the setup/index.php?action=welcome URI. | 2 | 7.5 | High | 2017-04-27 | 2017-03-31 | View |
Page 15805 of 17672, showing 5 records out of 88360 total, starting on record 79021, ending on 79025