NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
87952 | CVE-2017-2339 | A security researcher testing a Juniper NetScreen Firewall+VPN found multiple stored cross-site scripting vulnerabilities that could be used to elevate privileges through the NetScreen WebUI. A user with the 'security' role can inject HTML/JavaScript content into the management session of other users including the administrator. This enables the lower-privileged user to effectively execute commands with the permissions of an administrator. This issue affects Juniper Networks ScreenOS 6.3.0 releases prior to 6.3.0r24 on SSG Series. No other Juniper Networks products or platforms are affected by this issue. | 2017-07-18 | 2017-07-17 | View | ||||
88208 | CVE-2017-9529 | XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to a User Mode Write AV starting at Xfpx+0x0000000000004efd. | 2 | 6.8 | Medium | 2017-07-18 | 2017-07-10 | View | |
65937 | CVE-2005-0162 | Stack-based buffer overflow in the get_internal_addresses function in the pluto application for Openswan 1.x before 1.0.9, and Openswan 2.x before 2.3.0, when compiled with XAUTH and PAM enabled, allows remote authenticated attackers to execute arbitrary code. | 2 | 7.2 | High | 2017-07-18 | 2017-07-10 | View | |
66193 | CVE-2005-0435 | awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to read server web logs by setting the loadplugin and pluginmode parameters to rawlog. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
67217 | CVE-2005-1479 | SQL injection vulnerability in jgs_portal.php in JGS-Portal 3.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View |
Page 17073 of 17672, showing 5 records out of 88360 total, starting on record 85361, ending on 85365