NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
85936 | CVE-2017-5868 | CRLF injection vulnerability in the web interface in OpenVPN Access Server 2.1.4 allows remote attackers to inject arbitrary HTTP headers and consequently conduct session fixation attacks and possibly HTTP response splitting attacks via %0A characters in the PATH_INFO to __session_start__/. | 2 | 4.3 | Medium | 2017-06-12 | 2017-06-06 | View | |
86192 | CVE-2017-9068 | In MODX Revolution before 2.5.7, an attacker is able to trigger Reflected XSS by injecting payloads into several fields on the setup page, as demonstrated by the database_type parameter. | 2 | 4.3 | Medium | 2017-06-03 | 2017-05-30 | View | |
86448 | CVE-2016-9250 | In F5 BIG-IP 11.2.1, 11.4.0 through 11.6.1, and 12.0.0 through 12.1.2, an unauthenticated user with access to the control plane may be able to delete arbitrary files through an undisclosed mechanism. | 2 | 5 | Medium | 2017-05-27 | 2017-05-19 | View | |
86704 | CVE-2017-9474 | In ytnef 1.9.2, the DecompressRTF function in lib/ytnef.c allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file. | 2 | 4.3 | Medium | 2017-06-12 | 2017-06-09 | View | |
86960 | CVE-2017-6683 | A vulnerability in the esc_listener.py script of Cisco Elastic Services Controllers could allow an authenticated, remote attacker to execute arbitrary commands as the tomcat user on an affected system, aka an Authentication Request Processing Arbitrary Command Execution Vulnerability. More Information: CSCvc76642. Known Affected Releases: 2.2(9.76). | 2 | 9 | High | 2017-06-28 | 2017-06-23 | View |
Page 1587 of 17672, showing 5 records out of 88360 total, starting on record 7931, ending on 7935