NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
85499 | CVE-2017-7981 | Tuleap before 9.7 allows command injection via the PhpWiki 1.3.10 SyntaxHighlighter plugin. This occurs in the Project Wiki component because the proc_open PHP function is used within PhpWiki before 1.5.5 with a syntax value in its first argument, and an authenticated Tuleap user can control this value, even with shell metacharacters, as demonstrated by a '<?plugin SyntaxHighlighter syntax=c;id' line to execute the id command. | 2 | 9 | High | 2017-05-27 | 2017-05-11 | View | |
85755 | CVE-2017-0595 | An elevation of privilege vulnerability in libstagefright in Mediaserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-34705519. | 2 | 9.3 | High | 2017-05-27 | 2017-05-19 | View | |
86011 | CVE-2017-7213 | Zoho ManageEngine Desktop Central before build 100082 allows remote attackers to obtain control over all connected active desktops via unspecified vectors. | 2 | 10 | High | 2017-05-27 | 2017-05-22 | View | |
86267 | CVE-2017-9178 | libautotrace.a in AutoTrace 0.31.1 allows remote attackers to cause a denial of service (invalid write and SEGV), related to the ReadImage function in input-bmp.c:421:11. | 2 | 5 | Medium | 2017-06-03 | 2017-05-28 | View | |
86523 | CVE-2017-9349 | In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the DICOM dissector has an infinite loop. This was addressed in epan/dissectors/packet-dcm.c by validating a length value. | 2 | 7.8 | High | 2017-07-18 | 2017-07-07 | View |
Page 17416 of 17672, showing 5 records out of 88360 total, starting on record 87076, ending on 87080