NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 83655 | CVE-2016-9368 | An issue was discovered in Eaton xComfort Ethernet Communication Interface (ECI) Versions 1.07 and prior. By accessing a specific uniform resource locator (URL) on the webserver, a malicious user may be able to access files without authenticating. | 2 | 5 | Medium | 2017-03-18 | 2017-03-14 | View | |
| 82632 | CVE-2017-6303 | An issue was discovered in ytnef before 1.9.1. This is related to a patch described as 6 of 9. Invalid Write and Integer Overflow. | 2 | 6.8 | Medium | 2017-03-18 | 2017-03-01 | View | |
| 83144 | CVE-2017-2290 | On Windows installations of the mcollective-puppet-agent plugin, version 1.12.0, a non-administrator user can create an executable that will be executed with administrator privileges on the next mco puppet run. Puppet Enterprise users are not affected. This is resolved in mcollective-puppet-agent 1.12.1. | 2 | 9 | High | 2017-03-18 | 2017-03-13 | View | |
| 83400 | CVE-2017-6511 | andrzuk/FineCMS before 2017-03-06 is vulnerable to a reflected XSS in index.php because of missing validation of the action parameter in application/classes/application.php. | 2 | 4.3 | Medium | 2017-03-18 | 2017-03-09 | View | |
| 82121 | CVE-2016-9554 | The Sophos Web Appliance Remote / Secure Web Gateway server (version 4.2.1.3) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface. These vulnerabilities occur in MgrDiagnosticTools.php (/controllers/MgrDiagnosticTools.php), in the component responsible for performing diagnostic tests with the UNIX wget utility. The application doesn"t properly escape the information passed in the "url" variable before calling the executeCommand class function ($this->dtObj->executeCommand). This function calls exec() with unsanitized user input allowing for remote command injection. The page that contains the vulnerabilities, /controllers/MgrDiagnosticTools.php, is accessed by a built-in command answered by the administrative interface. The command that calls to that vulnerable page (passed in the "section" parameter) is: "configuration". Exploitation of this vulnerability yields shell access to the remote machine under the "spiderman" user account. | 2 | 9 | High | 2017-03-18 | 2017-03-13 | View |
Page 2047 of 17672, showing 5 records out of 88360 total, starting on record 10231, ending on 10235