NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
86625 | CVE-2017-5243 | The default SSH configuration in Rapid7 Nexpose hardware appliances shipped before June 2017 does not specify desired algorithms for key exchange and other important functions. As a result, it falls back to allowing ALL algorithms supported by the relevant version of OpenSSH and makes the installations vulnerable to a range of MITM, downgrade, and decryption attacks. | 2 | 6.8 | Medium | 2017-06-17 | 2017-06-14 | View | |
86633 | CVE-2017-7312 | An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1. When going to the /TabId/275 URI, anyone can add a vendor account or read existing vendor account data (including usernames and passwords). | 2 | 7.5 | High | 2017-06-17 | 2017-06-14 | View | |
86634 | CVE-2017-7313 | An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1. When going to the /TabId/275 URI, it is possible to read any customer name, master Customer Id, and email address. In other words, anyone can search for users/customers in the system - no authentication is required. | 2 | 5 | Medium | 2017-06-17 | 2017-06-14 | View | |
86635 | CVE-2017-7314 | An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1. When going to the /TabId/275 URI, while creating a new role, a list of database tables and their columns is available. | 2 | 5 | Medium | 2017-06-17 | 2017-06-14 | View | |
86642 | CVE-2017-8083 | CompuLab Intense PC and MintBox 2 devices with BIOS before 2017-05-21 do not use the CloseMnf protection mechanism for write protection of flash memory regions, which allows local users to install a firmware rootkit by leveraging administrative privileges. | 2 | 7.2 | High | 2017-06-17 | 2017-06-14 | View |
Page 16200 of 17672, showing 5 records out of 88360 total, starting on record 80996, ending on 81000