NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
85296 | CVE-2016-3104 | mongod in MongoDB 2.6, when using 2.4-style users, and 2.4 allow remote attackers to cause a denial of service (memory consumption and process termination) by leveraging in-memory database representation when authenticating against a non-existent database. | 2 | 5 | Medium | 2017-04-27 | 2017-04-22 | View | |
84785 | CVE-2017-7281 | An issue was discovered in Unitrends Enterprise Backup before 9.1.2. A lack of sanitization of user input in the createReportName and saveReport functions in recoveryconsole/bpl/reports.php allows for an authenticated user to create a randomly named file on disk with a user-controlled extension, contents, and path, leading to remote code execution, aka Unrestricted File Upload. | 2 | 6.5 | Medium | 2017-04-27 | 2017-04-20 | View | |
85297 | CVE-2016-3106 | Pulp before 2.8.3 creates a temporary directory during CA key generation in an insecure manner. | 2 | 5 | Medium | 2017-04-27 | 2017-04-26 | View | |
46897 | CVE-2012-5881 | Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.4.0 through 2.9.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to charts.swf, a similar issue to CVE-2010-4207. | 2 | 4.3 | Medium | 2017-04-27 | 2017-04-20 | View | |
84786 | CVE-2017-7282 | An issue was discovered in Unitrends Enterprise Backup before 9.1.1. The function downloadFile in api/includes/restore.php blindly accepts any filename passed to /api/restore/download as valid. This allows an authenticated attacker to read any file in the filesystem that the web server has access to, aka Local File Inclusion (LFI). | 2 | 7.1 | High | 2017-04-27 | 2017-04-24 | View |
Page 1766 of 17672, showing 5 records out of 88360 total, starting on record 8826, ending on 8830