NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
84865  CVE-2017-7572  The _checkPolkitPrivilege function in serviceHelper.py in Back In Time (aka backintime) 1.1.18 and earlier uses a deprecated polkit authorization method (unix-process) that is subject to a race condition (time of check, time of use). With this authorization method, the owner of a process requesting a polkit operation is checked by polkitd via /proc/<pid>/status, by which time the requesting process may have been replaced by a different process with the same PID that has different privileges then the original requester.    9.3  High  2017-04-27  2017-04-12  View
84868  CVE-2017-7576  DragonWave Horizon 1.01.03 wireless radios have hardcoded login credentials (such as the username of energetic and password of wireless) meant to allow the vendor to access the devices. These credentials can be used in the web interface or by connecting to the device via TELNET. This is fixed in recent versions including 1.4.8.    7.5  High  2017-04-27  2017-04-12  View
84869  CVE-2017-7577  XiongMai uc-httpd has directory traversal allowing the reading of arbitrary files via a GET ../ HTTP request.    Medium  2017-04-27  2017-04-12  View
84870  CVE-2017-7578  Multiple heap-based buffer overflows in parser.c in libming 0.4.7 allow remote attackers to cause a denial of service (listswf application crash) or possibly have unspecified other impact via a crafted SWF file. NOTE: this issue exists because of an incomplete fix for CVE-2016-9831.    6.8  Medium  2017-04-27  2017-04-12  View
84871  CVE-2017-7579  inc/PMF/Faq.php in phpMyFAQ before 2.9.7 has XSS in the question field.    4.3  Medium  2017-04-27  2017-04-12  View

Page 15835 of 17672, showing 5 records out of 88360 total, starting on record 79171, ending on 79175

Actions