NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
85936  CVE-2017-5868  CRLF injection vulnerability in the web interface in OpenVPN Access Server 2.1.4 allows remote attackers to inject arbitrary HTTP headers and consequently conduct session fixation attacks and possibly HTTP response splitting attacks via %0A characters in the PATH_INFO to __session_start__/.    4.3  Medium  2017-06-12  2017-06-06  View
86192  CVE-2017-9068  In MODX Revolution before 2.5.7, an attacker is able to trigger Reflected XSS by injecting payloads into several fields on the setup page, as demonstrated by the database_type parameter.    4.3  Medium  2017-06-03  2017-05-30  View
86448  CVE-2016-9250  In F5 BIG-IP 11.2.1, 11.4.0 through 11.6.1, and 12.0.0 through 12.1.2, an unauthenticated user with access to the control plane may be able to delete arbitrary files through an undisclosed mechanism.    Medium  2017-05-27  2017-05-19  View
86704  CVE-2017-9474  In ytnef 1.9.2, the DecompressRTF function in lib/ytnef.c allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.    4.3  Medium  2017-06-12  2017-06-09  View
86960  CVE-2017-6683  A vulnerability in the esc_listener.py script of Cisco Elastic Services Controllers could allow an authenticated, remote attacker to execute arbitrary commands as the tomcat user on an affected system, aka an Authentication Request Processing Arbitrary Command Execution Vulnerability. More Information: CSCvc76642. Known Affected Releases: 2.2(9.76).    High  2017-06-28  2017-06-23  View

Page 1587 of 17672, showing 5 records out of 88360 total, starting on record 7931, ending on 7935

Actions