NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
84801 | CVE-2017-7323 | The (1) update and (2) package-installation features in MODX Revolution 2.5.4-pl and earlier use http://rest.modx.com by default, which allows man-in-the-middle attackers to spoof servers and trigger the execution of arbitrary code by leveraging the lack of the HTTPS protection mechanism. | 2 | 6.8 | Medium | 2017-04-27 | 2017-03-31 | View | |
84802 | CVE-2017-7324 | setup/templates/findcore.php in MODX Revolution 2.5.4-pl and earlier allows remote attackers to execute arbitrary PHP code via the core_path parameter. | 2 | 7.5 | High | 2017-04-27 | 2017-03-31 | View | |
84803 | CVE-2017-7345 | NetApp OnCommand Performance Manager and OnCommand Unified Manager for Clustered Data ONTAP before 7.1P1 improperly bind the Java Management Extension Remote Method Invocation (aka JMX RMI) service to the network, which allows remote attackers to obtain sensitive information via unspecified vectors. | 2 | 5 | Medium | 2017-04-27 | 2017-04-17 | View | |
84804 | CVE-2017-7346 | The vmw_gb_surface_define_ioctl function in drivers/gpu/drm/vmwgfx/vmwgfx_surface.c in the Linux kernel through 4.10.7 does not validate certain levels data, which allows local users to cause a denial of service (system hang) via a crafted ioctl call for a /dev/dri/renderD* device. | 2 | 4.9 | Medium | 2017-04-27 | 2017-04-04 | View | |
84805 | CVE-2017-7357 | Hipchat Server before 2.2.3 allows remote authenticated users with Server Administrator level privileges to execute arbitrary code by importing a file. | 2 | 6.5 | Medium | 2017-04-27 | 2017-04-25 | View |
Page 16961 of 17672, showing 5 records out of 88360 total, starting on record 84801, ending on 84805