NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
82862  CVE-2016-9683  The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface. This vulnerability occurs in the "extensionsettings" CGI (/cgi-bin/extensionsettings) component responsible for handling some of the server"s internal configurations. The CGI application doesn"t properly escape the information it"s passed when processing a particular multi-part form request involving scripts. The filename of the "scriptname" variable is read in unsanitized before a call to system() is performed - allowing for remote command injection. Exploitation of this vulnerability yields shell access to the remote machine under the nobody user account. This is SonicWall Issue ID 181195.    10  High  2017-02-28  2017-02-23  View
82863  CVE-2016-9684  The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface. This vulnerability occurs in the "viewcert" CGI (/cgi-bin/viewcert) component responsible for processing SSL certificate information. The CGI application doesn"t properly escape the information it"s passed in the "CERT" variable before a call to system() is performed - allowing for remote command injection. Exploitation of this vulnerability yields shell access to the remote machine under the nobody user account.    10  High  2017-02-28  2017-02-23  View
82610  CVE-2017-6078  FastStone MaxView 3.0 and 3.1 allows user-assisted attackers to cause a denial of service (application crash) via a malformed BMP image with a crafted biSize field in the BITMAPINFOHEADER section.    4.3  Medium  2017-02-28  2017-02-23  View
82868  CVE-2016-9909  The serializer in html5lib before 0.99999999 might allow remote attackers to conduct cross-site scripting (XSS) attacks by leveraging mishandling of the < (less than) character in attribute values.    4.3  Medium  2017-02-28  2017-02-23  View
82869  CVE-2016-9910  The serializer in html5lib before 0.99999999 might allow remote attackers to conduct cross-site scripting (XSS) attacks by leveraging mishandling of special characters in attribute values, a different vulnerability than CVE-2016-9909.    4.3  Medium  2017-02-28  2017-02-23  View

Page 2103 of 17672, showing 5 records out of 88360 total, starting on record 10511, ending on 10515

Actions