NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
86668  CVE-2017-9324  In Open Ticket Request System (OTRS) 3.3.x through 3.3.16, 4.x through 4.0.23, and 5.x through 5.0.19, an attacker with agent permission is capable of opening a specific URL in a browser to gain administrative privileges / full access. Afterward, all system settings can be read and changed. The URLs in question contain index.pl?Action=Installer with ;Subaction=Intro or ;Subaction=Start or ;Subaction=System appended at the end.    6.5  Medium  2017-06-23  2017-06-22  View
86927  CVE-2017-4961  An issue was discovered in Cloud Foundry Foundation BOSH Release 261.x versions prior to 261.3 and all 260.x versions. In certain cases an authenticated Director user can provide a malicious checksum that could allow them to escalate their privileges on the Director VM, aka BOSH Director Shell Injection Vulnerabilities.    6.5  Medium  2017-06-23  2017-06-22  View
83623  CVE-2016-10248  The jpc_tsfb_synthesize function in jpc_tsfb.c in JasPer before 1.900.9 allows remote attackers to cause a denial of service (NULL pointer dereference) via vectors involving an empty sequence.    Medium  2017-06-23  2017-06-22  View
87214  CVE-2016-3696  The pulp-qpid-ssl-cfg script in Pulp before 2.8.5 allows local users to obtain the CA key.    2.1  Low  2017-06-23  2017-06-22  View
87215  CVE-2016-3704  Pulp before 2.8.5 uses bash's $RANDOM in an unsafe way to generate passwords.    Medium  2017-06-23  2017-06-22  View

Page 16252 of 17672, showing 5 records out of 88360 total, starting on record 81256, ending on 81260

Actions