NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
4450 | CVE-2008-4636 | yast2-backup 2.14.2 through 2.16.6 on SUSE Linux and Novell Linux allows local users to gain privileges via shell metacharacters in filenames used by the backup process. | 2 | 7.2 | High | 2017-01-03 | 2008-12-03 | View | |
17954 | CVE-2016-1601 | yast2-users before 3.1.47, as used in SUSE Linux Enterprise 12 SP1, does not properly set empty password fields in /etc/shadow during an AutoYaST installation when the profile does not contain inst-sys users, which might allow attackers to have unspecified impact via unknown vectors. | 2 | 10 | High | 2017-01-19 | 2016-11-30 | View | |
51617 | CVE-2009-4495 | Yaws 1.85 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window"s title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator. | 2 | 5 | Medium | 2017-01-07 | 2012-02-29 | View | |
87751 | CVE-2017-10974 | Yaws 1.91 allows Unauthenticated Remote File Disclosure via HTTP Directory Traversal with /%5C../ to port 8080. NOTE: this CVE is only about use of an initial /%5C sequence to defeat traversal protection mechanisms; the initial /%5C sequence was apparently not discussed in earlier research on this product. | 2 | 5 | Medium | 2017-07-18 | 2017-07-14 | View | |
48070 | CVE-2009-0751 | Yaws before 1.80 allows remote attackers to cause a denial of service (memory consumption and crash) via a request with a large number of headers. | 2 | 5 | Medium | 2017-01-07 | 2010-04-27 | View |
Page 17629 of 17672, showing 5 records out of 88360 total, starting on record 88141, ending on 88145