NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
84687 | CVE-2017-5607 | Splunk Enterprise 5.0.x before 5.0.18, 6.0.x before 6.0.14, 6.1.x before 6.1.13, 6.2.x before 6.2.13.1, 6.3.x before 6.3.10, 6.4.x before 6.4.6, and 6.5.x before 6.5.3 and Splunk Light before 6.5.2 assigns the $C JS property to the global Window namespace, which might allow remote attackers to obtain sensitive logged-in username and version-related information via a crafted webpage. | 2 | 4.3 | Medium | 2017-04-27 | 2017-04-17 | View | |
84702 | CVE-2017-5672 | Kony Enterprise Mobile Management (EMM) before 4.2.5.2 has the vulnerability of disclosing the private key in clear-text when changing the parameters of the request. | 2 | 4 | Medium | 2017-04-27 | 2017-04-17 | View | |
84707 | CVE-2017-5873 | Unquoted Windows search path vulnerability in the guest service in Unisys s-Par before 4.4.20 allows local users to gain privileges via a Trojan horse executable file in the %SYSTEMDRIVE% directory, as demonstrated by program.exe. | 2 | 4.6 | Medium | 2017-04-27 | 2017-04-17 | View | |
84736 | CVE-2017-6412 | In Sophos Web Appliance (SWA) before 4.3.1.2, Session Fixation could occur, aka NSWA-1310. | 2 | 6.8 | Medium | 2017-04-27 | 2017-04-14 | View | |
84768 | CVE-2017-7185 | Use-after-free vulnerability in the mg_http_multipart_wait_for_boundary function in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.7 and earlier and Mongoose OS 1.2 and earlier allows remote attackers to cause a denial of service (crash) via a multipart/form-data POST request without a MIME boundary string. | 2 | 5 | Medium | 2017-04-27 | 2017-04-14 | View |
Page 1827 of 17672, showing 5 records out of 88360 total, starting on record 9131, ending on 9135