NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
86633 | CVE-2017-7312 | An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1. When going to the /TabId/275 URI, anyone can add a vendor account or read existing vendor account data (including usernames and passwords). | 2 | 7.5 | High | 2017-06-17 | 2017-06-14 | View | |
86634 | CVE-2017-7313 | An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1. When going to the /TabId/275 URI, it is possible to read any customer name, master Customer Id, and email address. In other words, anyone can search for users/customers in the system - no authentication is required. | 2 | 5 | Medium | 2017-06-17 | 2017-06-14 | View | |
86635 | CVE-2017-7314 | An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1. When going to the /TabId/275 URI, while creating a new role, a list of database tables and their columns is available. | 2 | 5 | Medium | 2017-06-17 | 2017-06-14 | View | |
86636 | CVE-2017-7515 | poppler through version 0.55.0 is vulnerable to an uncontrolled recursion in pdfunite resulting into potential denial-of-service. | 2 | 4.3 | Medium | 2017-06-17 | 2017-06-12 | View | |
86637 | CVE-2017-7563 | In ARM Trusted Firmware 1.3, RO memory is always executable at AArch64 Secure EL1, allowing attackers to bypass the MT_EXECUTE_NEVER protection mechanism. This issue occurs because of inconsistency in the number of execute-never bits (one bit versus two bits). | 2 | 6.8 | Medium | 2017-06-17 | 2017-06-15 | View |
Page 16182 of 17672, showing 5 records out of 88360 total, starting on record 80906, ending on 80910