NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
81665  CVE-2017-5595  A file disclosure and inclusion vulnerability exists in web/views/file.php in ZoneMinder 1.x through v1.30.0 because of unfiltered user-input being passed to readfile(), which allows an authenticated attacker to read local system files (e.g., /etc/passwd) in the context of the web server user (www-data). The attack vector is a .. (dot dot) in the path parameter within a zm/index.php?view=file&path= request.    2.1  Low  2017-02-28  2017-02-16  View
82177  CVE-2017-2969  Adobe Campaign versions 16.4 Build 8724 and earlier have a cross-site scripting (XSS) vulnerability.    4.3  Medium  2017-03-18  2017-02-28  View
17409  CVE-2016-1000216  Ruckus Wireless H500 web management interface authenticated command injection    High  2017-06-28  2017-06-28  View
82945  CVE-2017-0025  The kernel-mode drivers in Microsoft Windows Vista; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allow local users to gain privileges via a crafted application, aka Win32k Elevation of Privilege Vulnerability. This vulnerability is different from those described in CVE-2017-0001, CVE-2017-0005, and CVE-2017-0047.    7.2  High  2017-07-18  2017-07-11  View
83201  CVE-2017-5496  Sawmill Enterprise 8.7.9 allows remote attackers to gain login access by leveraging knowledge of a password hash.    Medium  2017-03-29  2017-03-21  View

Page 234 of 17672, showing 5 records out of 88360 total, starting on record 1166, ending on 1170

Actions