NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
84761  CVE-2017-6884  A command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware V1.00(AAQT.4)b8. The vulnerability is located in the diagnostic tools, specifically the nslookup function. A malicious user may exploit numerous vectors to execute arbitrary commands on the router, such as the ping_ip parameter to the expert/maintenance/diagnostic/nslookup URI.    High  2017-04-27  2017-04-12  View
19481  CVE-2016-3713  The msr_mtrr_valid function in arch/x86/kvm/mtrr.c in the Linux kernel before 4.6.1 supports MSR 0x2f8, which allows guest OS users to read or write to the kvm_arch_vcpu data structure, and consequently obtain sensitive information or cause a denial of service (system crash), via a crafted ioctl call.    5.6  Medium  2017-01-19  2016-06-27  View
85017  CVE-2017-8052  Craft CMS before 2.6.2974 allows XSS attacks.    4.3  Medium  2017-04-27  2017-04-26  View
19737  CVE-2016-4015  The Enqueue Server in SAP NetWeaver JAVA AS 7.1 through 7.4 allows remote attackers to cause a denial of service (process crash) via a crafted request, aka SAP Security Note 2258784.    Medium  2017-01-19  2016-04-19  View
85273  CVE-2016-10324  In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the osip_clrncpy() function defined in osipparser2/osip_port.c.    7.5  High  2017-04-27  2017-04-19  View

Page 1727 of 17672, showing 5 records out of 88360 total, starting on record 8631, ending on 8635

Actions