NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
86625  CVE-2017-5243  The default SSH configuration in Rapid7 Nexpose hardware appliances shipped before June 2017 does not specify desired algorithms for key exchange and other important functions. As a result, it falls back to allowing ALL algorithms supported by the relevant version of OpenSSH and makes the installations vulnerable to a range of MITM, downgrade, and decryption attacks.    6.8  Medium  2017-06-17  2017-06-14  View
86633  CVE-2017-7312  An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1. When going to the /TabId/275 URI, anyone can add a vendor account or read existing vendor account data (including usernames and passwords).    7.5  High  2017-06-17  2017-06-14  View
86634  CVE-2017-7313  An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1. When going to the /TabId/275 URI, it is possible to read any customer name, master Customer Id, and email address. In other words, anyone can search for users/customers in the system - no authentication is required.    Medium  2017-06-17  2017-06-14  View
86635  CVE-2017-7314  An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1. When going to the /TabId/275 URI, while creating a new role, a list of database tables and their columns is available.    Medium  2017-06-17  2017-06-14  View
86642  CVE-2017-8083  CompuLab Intense PC and MintBox 2 devices with BIOS before 2017-05-21 do not use the CloseMnf protection mechanism for write protection of flash memory regions, which allows local users to install a firmware rootkit by leveraging administrative privileges.    7.2  High  2017-06-17  2017-06-14  View

Page 16200 of 17672, showing 5 records out of 88360 total, starting on record 80996, ending on 81000

Actions