NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
87097 | CVE-2017-9552 | A design flaw in authentication in Synology Photo Station 6.0-2528 through 6.7.1-3419 allows local users to obtain credentials via cmdline. Synology Photo Station employs the synophoto_dsm_user program to authenticate username and password by synophoto_dsm_user --auth USERNAME PASSWORD, and local users are able to obtain credentials by sniffing /proc/*/cmdline. | 2 | 2.1 | Low | 2017-07-18 | 2017-07-03 | View | |
87353 | CVE-2017-1193 | IBM Sterling B2B Integrator Standard Edition 5.2 could allow user to obtain sensitive information using an HTTP GET request. IBM X-Force ID: 123667. | 2 | 4 | Medium | 2017-06-28 | 2017-06-26 | View | |
87609 | CVE-2017-1000072 | Creolabs Gravity version 1.0 is vulnerable to a Double Free in gravity_value resulting potentially leading to modification of unexpected memory locations | 2017-07-18 | 2017-07-17 | View | ||||
87865 | CVE-2017-11419 | Fiyo CMS 2.0.7 has SQL injection in /apps/app_article/controller/editor.php via $_POST['id'] and $_POST['art_title']. | 2017-07-18 | 2017-07-18 | View | ||||
88121 | CVE-2017-8034 | The Cloud Controller and Router in Cloud Foundry (CAPI-release capi versions prior to v1.32.0, Routing-release versions prior to v0.159.0, CF-release versions prior to v267) do not validate the issuer on JSON Web Tokens (JWTs) from UAA. With certain multi-zone UAA configurations, zone administrators are able to escalate their privileges. | 2017-07-18 | 2017-07-17 | View |
Page 15945 of 17672, showing 5 records out of 88360 total, starting on record 79721, ending on 79725