NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 85947 | CVE-2017-6051 | An Uncontrolled Search Path Element issue was discovered in BLF-Tech LLC VisualView HMI Version 9.9.14.0 and prior. The uncontrolled search path element vulnerability has been identified, which may allow an attacker to run a malicious DLL file within the search path resulting in execution of arbitrary code. | 2 | 5.1 | Medium | 2017-05-27 | 2017-05-18 | View | |
| 86203 | CVE-2017-9079 | Dropbear before 2017.75 might allow local users to read certain files as root, if the file has the authorized_keys file format with a command= option. This occurs because ~/.ssh/authorized_keys is read with root privileges and symlinks are followed. | 2 | 4.7 | Medium | 2017-05-27 | 2017-05-24 | View | |
| 85692 | CVE-2017-0242 | An information disclosure vulnerability exists in the way some ActiveX objects are instantiated, aka Microsoft ActiveX Information Disclosure Vulnerability. | 2 | 4.3 | Medium | 2017-05-27 | 2017-05-23 | View | |
| 85948 | CVE-2017-6079 | The HTTP web-management application on Edgewater Networks Edgemarc appliances has a hidden page that allows for user-defined commands such as specific iptables routes, etc., to be set. You can use this page as a web shell essentially to execute commands, though you get no feedback client-side from the web application: if the command is valid, it executes. An example is the wget command. The page that allows this has been confirmed in firmware as old as 2006. | 2 | 10 | High | 2017-05-27 | 2017-05-25 | View | |
| 85437 | CVE-2017-5135 | Certain Technicolor devices have an SNMP access-control bypass, possibly involving an ISP customization in some cases. The Technicolor (formerly Cisco) DPC3928SL with firmware D3928SL-P15-13-A386-c3420r55105-160127a could be reached by any SNMP community string from the Internet; also, you can write in the MIB because it provides write properties, aka Stringbleed. NOTE: the string-bleed/StringBleed-CVE-2017-5135 GitHub repository is not a valid reference as of 2017-04-27; it contains Trojan horse code purported to exploit this vulnerability. | 2 | 6.4 | Medium | 2017-05-27 | 2017-05-11 | View |
Page 16062 of 17672, showing 5 records out of 88360 total, starting on record 80306, ending on 80310