NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
86960 | CVE-2017-6683 | A vulnerability in the esc_listener.py script of Cisco Elastic Services Controllers could allow an authenticated, remote attacker to execute arbitrary commands as the tomcat user on an affected system, aka an Authentication Request Processing Arbitrary Command Execution Vulnerability. More Information: CSCvc76642. Known Affected Releases: 2.2(9.76). | 2 | 9 | High | 2017-06-28 | 2017-06-23 | View | |
84221 | CVE-2017-1152 | IBM Financial Transaction Manager 3.0.1 and 3.0.2 does not properly update the SESSIONID with each request, which could allow a user to obtain the ID in further attacks against the system. IBM X-Force ID: 122293. | 2 | 4 | Medium | 2017-06-28 | 2017-06-23 | View | |
83355 | CVE-2017-6445 | The auto-update feature of Open Embedded Linux Entertainment Center (OpenELEC) 6.0.3, 7.0.1, and 8.0.4 uses neither encrypted connections nor signed updates. A man-in-the-middle attacker could manipulate the update packages to gain root access remotely. | 2 | 7.6 | High | 2017-06-28 | 2017-06-25 | View | |
87049 | CVE-2017-8508 | A security feature bypass vulnerability exists in Microsoft Office software when it improperly handles the parsing of file formats, aka Microsoft Office Security Feature Bypass Vulnerability. | 2 | 4.3 | Medium | 2017-06-28 | 2017-06-26 | View | |
87311 | CVE-2017-9742 | The score_opcodes function in opcodes/score7-dis.c in GNU Binutils 2.28 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of this file during objdump -D execution. | 2 | 6.8 | Medium | 2017-06-28 | 2017-06-26 | View |
Page 16258 of 17672, showing 5 records out of 88360 total, starting on record 81286, ending on 81290