NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
83485  CVE-2017-6903  In ioquake3 before 2017-03-14, the auto-downloading feature has insufficient content restrictions. This also affects Quake III Arena, OpenArena, OpenJK, iortcw, and other id Tech 3 (aka Quake 3 engine) forks. A malicious auto-downloaded file can trigger loading of crafted auto-downloaded files as native code DLLs. A malicious auto-downloaded file can contain configuration defaults that override the user's. Executable bytecode in a malicious auto-downloaded file can set configuration variables to values that will result in unwanted native code DLLs being loaded, resulting in sandbox escape.    9.3  High  2017-03-29  2017-03-28  View
83484  CVE-2017-6902  ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.        2017-03-18  2017-03-17  View
86976  CVE-2017-6899  The msm_bus_dbg_update_request_write function in drivers/platform/msm/msm_bus/msm_bus_dbg.c in android_kernel_huawei_msm8916 through 2017-06-16 in LineageOS, and possibly other kernels for MSM devices, allows attackers to cause a denial of service (NULL pointer dereference and device crash) via a crafted /sys/kernel/debug/msm-bus-dbg/client-data/update-request write request.    4.9  Medium  2017-07-18  2017-07-05  View
83483  CVE-2017-6896  Privilege escalation vulnerability on the DIGISOL DG-HR1400 1.00.02 wireless router enables an attacker to escalate from user privilege to admin privilege just by modifying the Base64-encoded session cookie value.    6.5  Medium  2017-03-29  2017-03-24  View
83803  CVE-2017-6895  USB Pratirodh allows remote attackers to conduct XML External Entity (XXE) attacks via XML data in usb.xml.    7.5  High  2017-03-29  2017-03-28  View

Page 314 of 17672, showing 5 records out of 88360 total, starting on record 1566, ending on 1570

Actions