NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
87334 | CVE-2017-9774 | Remote Code Execution was found in Horde_Image 2.x before 2.5.0 via a crafted GET request. Exploitation requires authentication. | 2 | 6.5 | Medium | 2017-07-18 | 2017-07-03 | View | |
87338 | CVE-2017-9780 | In Flatpak before 0.8.7, a third-party app repository could include malicious apps that contain files with inappropriate permissions, for example setuid or world-writable. The files are deployed with those permissions, which would let a local attacker run the setuid executable or write to the world-writable location. In the case of the system helper component, files deployed as part of the app are owned by root, so in the worst case they could be setuid root. | 2 | 7.2 | High | 2017-07-18 | 2017-07-03 | View | |
87341 | CVE-2017-9807 | An issue was discovered in the OpenWebif plugin through 1.2.4 for E2 open devices. The saveConfig function of plugin/controllers/models/config.py performs an eval() call on the contents of the key HTTP GET parameter. This allows an unauthenticated remote attacker to execute arbitrary Python code or OS commands via api/saveconfig. | 2 | 10 | High | 2017-07-18 | 2017-07-03 | View | |
87096 | CVE-2017-9505 | Atlassian Confluence starting with 4.3.0 before 6.2.1 did not check if a user had permission to view a page when creating a workbox notification about new comments. An attacker who can login to Confluence could receive workbox notifications, which contain the content of comments, for comments added to a page after they started watching it even if they do not have permission to view the page itself. | 2 | 4 | Medium | 2017-07-18 | 2017-07-03 | View | |
87097 | CVE-2017-9552 | A design flaw in authentication in Synology Photo Station 6.0-2528 through 6.7.1-3419 allows local users to obtain credentials via cmdline. Synology Photo Station employs the synophoto_dsm_user program to authenticate username and password by synophoto_dsm_user --auth USERNAME PASSWORD, and local users are able to obtain credentials by sniffing /proc/*/cmdline. | 2 | 2.1 | Low | 2017-07-18 | 2017-07-03 | View |
Page 16346 of 17672, showing 5 records out of 88360 total, starting on record 81726, ending on 81730