NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
87288 | CVE-2017-3744 | In the IMM2 firmware of Lenovo System x servers, remote commands issued by LXCA or other utilities may be captured in the First Failure Data Capture (FFDC) service log if the service log is generated when that remote command is running. Captured command data may contain clear text login information. Authorized users that can capture and export FFDC service log data may have access to these remote commands. | 2 | 4 | Medium | 2017-07-18 | 2017-07-05 | View | |
87544 | CVE-2017-1000004 | ATutor versions 2.2.1 and earlier are vulnerable to a SQL injection vulnerability in the Assignment Dropbox component resulting in information disclosure, database modification, or potential code execution. ATutor versions 2.2.1 and older are vulnerable to a SQL injection in the BasicLTI component resulting in information disclosure, database modification or potential code execution. ATutor version 2.2.1 and older is vulnerable to a SQL injection vulnerability in the Blog Post component resulting in information disclosure, database modification or potential code execution. ATutor versions 2.2.1 and earlier are vulnerable to a SQL injection vulnerability in the Blog component resulting in information disclosure, database modification or potential code execution. ATutor versions 2.2.1 and earlier are vulnerable to a SQL injection in the Group Course Email component resulting in information disclosure, database modification or potential code execution. ATutor versions 2.2.1 and earlier are vulnerable to a SQL injection vulnerability in the Course Alumni component resulting in information disclosure, database modification or potential code execution. ATutor versions 2.2.1 and earlier are vulnerable to a SQL injection vulnerability in the Course Enrolment component resulting in information disclosure, database modification or potential code execution. ATutor versions 2.2.1 and earlier are vulnerable to a SQL injection vulnerability in the Group Membership component resulting in information disclosure, database modification, or potential code execution. ATutor versions 2.2.1 and earlier are vulnerable to a SQL injection vulnerability in the Course unenrolment component resulting in information disclosure, database modification, or potential code execution. ATutor versions 2.2.1 and earlier are vulnerable to a SQL Injection vulnerability in the Course Enrolment List Search component resulting in information disclosure, database modification, or potential code execution. ATutor versions 2.2.1 and earlier are vulnerable to a SQL injection vulnerability in the Glossary component resulting in information disclosure, database modification, or potential code execution. ATutor versions 2.2.1 and earlier are vulnerable to a SQL injection in the Social Group Member Search component resulting in information disclosure, database modification, or potential code execution. ATutor versions 2.2.1 and earlier are vulnerable to a SQL injection vulnerability in the Social Friend Search component resulting in information disclosure, database modification, or potential code execution. ATutor versions 2.2.1 and earlier are vulnerable to a SQL injection vulnerability in the Social Group Search component resulting in information disclosure, database modification, or potential code execution. ATutor versions 2.2.1 and earlier are vulnerable to a SQL injection vulnerability in the File Comment component resulting in information disclosure, database modification, or potential code execution. ATutor versions 2.2.1 and earlier are vulnerable to a SQL injection vulnerability in the Gradebook Test Title component resulting in information disclosure, database modification, or potential code execution. ATutor versions 2.2.1 and earlier are vulnerable to a SQL injection vulnerability in the User Group Membership component resulting in information disclosure, database modification, or potential code execution. ATutor versions 2.2.1 and earlier are vulnerable to a SQL injection vulnerability in the Inbox/Sent Items component resulting in information disclosure, database modification, or potential code execution. ATutor versions 2.2.1 and earlier are vulnerable to a SQL injection vulnerability in the Sent Messages component resulting in information disclosure, database modification, or potential code execution. ATutor versions 2.2.1 and earlier are vulnerable to a SQL in | 2017-07-18 | 2017-07-17 | View | ||||
87800 | CVE-2017-11163 | Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in Cacti 1.1.12 allows remote authenticated users to inject arbitrary web script or HTML via specially crafted HTTP Referer headers, related to the $cancel_url variable. | 2 | 3.5 | Low | 2017-07-18 | 2017-07-17 | View | |
88056 | CVE-2017-6731 | A vulnerability in Multicast Source Discovery Protocol (MSDP) ingress packet processing for Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause the MSDP session to be unexpectedly reset, causing a short denial of service (DoS) condition. The MSDP session will restart within a few seconds. More Information: CSCvd94828. Known Affected Releases: 4.3.2.MCAST 6.0.2.BASE. Known Fixed Releases: 6.3.1.19i.MCAST 6.2.3.1i.MCAST 6.2.2.17i.MCAST 6.1.4.12i.MCAST. | 2 | 5 | Medium | 2017-07-18 | 2017-07-16 | View | |
88312 | CVE-2016-8638 | A vulnerability in ipsilon 2.0 before 2.0.2, 1.2 before 1.2.1, 1.1 before 1.1.2, and 1.0 before 1.0.3 was found that allows attacker to log out active sessions of other users. This issue is related to how it tracks sessions, and allows an unauthenticated attacker to view and terminate active sessions from other users. | 2 | 6.4 | Medium | 2017-07-18 | 2017-07-17 | View |
Page 17633 of 17672, showing 5 records out of 88360 total, starting on record 88161, ending on 88165