NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
86714 | CVE-2017-9525 | In the cron package through 3.0pl1-128 on Debian, and through 3.0pl1-128ubuntu2 on Ubuntu, the postinst maintainer script allows for group-crontab-to-root privilege escalation via symlink attacks against unsafe usage of the chown and chmod programs. | 2 | 10 | High | 2017-07-18 | 2017-07-07 | View | |
86715 | CVE-2017-9526 | In Libgcrypt before 1.7.7, an attacker who learns the EdDSA session key (from side-channel observation during the signing process) can easily recover the long-term secret key. 1.7.7 makes a cipher/ecc-eddsa.c change to store this session key in secure memory, to ensure that constant-time point operations are used in the MPI library. | 2 | 4.3 | Medium | 2017-06-23 | 2017-06-22 | View | |
86716 | CVE-2017-9527 | The mark_context_stack function in gc.c in mruby through 1.2.0 allows attackers to cause a denial of service (heap-based use-after-free and application crash) or possibly have unspecified other impact via a crafted .rb file. | 2 | 6.8 | Medium | 2017-06-23 | 2017-06-22 | View | |
88207 | CVE-2017-9528 | IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows remote attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to a User Mode Write AV starting at FPX!FPX_GetScanDevicePropertyGroup+0x0000000000000f53. | 2 | 6.8 | Medium | 2017-07-18 | 2017-07-11 | View | |
88208 | CVE-2017-9529 | XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to a User Mode Write AV starting at Xfpx+0x0000000000004efd. | 2 | 6.8 | Medium | 2017-07-18 | 2017-07-10 | View |
Page 17624 of 17672, showing 5 records out of 88360 total, starting on record 88116, ending on 88120