NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 81631 | CVE-2017-5368 | ZoneMinder v1.30 and v1.29, an open-source CCTV server web application, is vulnerable to CSRF (Cross Site Request Forgery) which allows a remote attack to make changes to the web application as the current logged in victim. If the victim visits a malicious web page, the attacker can silently and automatically create a new admin user within the web application for remote persistence and further attacks. The URL is /zm/index.php and sample parameters could include action=user uid=0 newUser[Username]=attacker1 newUser[Password]=Password1234 conf_password=Password1234 newUser[System]=Edit (among others). | 2 | 6.8 | Medium | 2017-02-15 | 2017-02-09 | View | |
| 81646 | CVE-2017-5546 | The freelist-randomization feature in mm/slab.c in the Linux kernel 4.8.x and 4.9.x before 4.9.5 allows local users to cause a denial of service (duplicate freelist entries and system crash) or possibly have unspecified other impact in opportunistic circumstances by leveraging the selection of a large value for a random number. | 2 | 7.2 | High | 2017-02-15 | 2017-02-09 | View | |
| 81902 | CVE-2016-8918 | IBM Integration Bus, under non default configurations, could allow a remote user to authenticate without providing valid credentials. | 2 | 4.3 | Medium | 2017-02-15 | 2017-02-09 | View | |
| 81647 | CVE-2017-5547 | drivers/hid/hid-corsair.c in the Linux kernel 4.9.x before 4.9.6 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (system crash or memory corruption) or possibly have unspecified other impact by leveraging use of more than one virtual page for a DMA scatterlist. | 2 | 7.2 | High | 2017-02-15 | 2017-02-09 | View | |
| 81650 | CVE-2017-5550 | Off-by-one error in the pipe_advance function in lib/iov_iter.c in the Linux kernel before 4.9.5 allows local users to obtain sensitive information from uninitialized heap-memory locations in opportunistic circumstances by reading from a pipe after an incorrect buffer-release decision. | 2 | 2.1 | Low | 2017-02-15 | 2017-02-09 | View |
Page 2233 of 17672, showing 5 records out of 88360 total, starting on record 11161, ending on 11165