NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
85932  CVE-2017-5646  For versions of Apache Knox from 0.2.0 to 0.11.0 - an authenticated user may use a specially crafted URL to impersonate another user while accessing WebHDFS through Apache Knox. This may result in escalated privileges and unauthorized data access. While this activity is audit logged and can be easily associated with the authenticated user, this is still a serious security issue. All users are recommended to upgrade to the Apache Knox 0.12.0 release.    4.9  Medium  2017-06-12  2017-06-08  View
86700  CVE-2017-9470  In ytnef 1.9.2, the MAPIPrint function in lib/ytnef.c allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file.    4.3  Medium  2017-06-12  2017-06-09  View
86701  CVE-2017-9471  In ytnef 1.9.2, the SwapWord function in lib/ytnef.c allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.    4.3  Medium  2017-06-12  2017-06-09  View
86702  CVE-2017-9472  In ytnef 1.9.2, the SwapDWord function in lib/ytnef.c allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.    4.3  Medium  2017-06-12  2017-06-09  View
86703  CVE-2017-9473  In ytnef 1.9.2, the TNEFFillMapi function in lib/ytnef.c allows remote attackers to cause a denial of service (memory consumption) via a crafted file.    4.3  Medium  2017-06-12  2017-06-09  View

Page 16159 of 17672, showing 5 records out of 88360 total, starting on record 80791, ending on 80795

Actions