NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
81665 | CVE-2017-5595 | A file disclosure and inclusion vulnerability exists in web/views/file.php in ZoneMinder 1.x through v1.30.0 because of unfiltered user-input being passed to readfile(), which allows an authenticated attacker to read local system files (e.g., /etc/passwd) in the context of the web server user (www-data). The attack vector is a .. (dot dot) in the path parameter within a zm/index.php?view=file&path= request. | 2 | 2.1 | Low | 2017-02-28 | 2017-02-16 | View | |
82177 | CVE-2017-2969 | Adobe Campaign versions 16.4 Build 8724 and earlier have a cross-site scripting (XSS) vulnerability. | 2 | 4.3 | Medium | 2017-03-18 | 2017-02-28 | View | |
17409 | CVE-2016-1000216 | Ruckus Wireless H500 web management interface authenticated command injection | 2 | 9 | High | 2017-06-28 | 2017-06-28 | View | |
82945 | CVE-2017-0025 | The kernel-mode drivers in Microsoft Windows Vista; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allow local users to gain privileges via a crafted application, aka Win32k Elevation of Privilege Vulnerability. This vulnerability is different from those described in CVE-2017-0001, CVE-2017-0005, and CVE-2017-0047. | 2 | 7.2 | High | 2017-07-18 | 2017-07-11 | View | |
83201 | CVE-2017-5496 | Sawmill Enterprise 8.7.9 allows remote attackers to gain login access by leveraging knowledge of a password hash. | 2 | 5 | Medium | 2017-03-29 | 2017-03-21 | View |
Page 234 of 17672, showing 5 records out of 88360 total, starting on record 1166, ending on 1170