NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
87362 | CVE-2017-9829 | /cgi-bin/admin/downloadMedias.cgi' of the web service in most of the VIVOTEK Network Cameras is vulnerable, which allows remote attackers to read any file on the camera's Linux filesystem via a crafted HTTP request containing .. sequences. This vulnerability is already verified on VIVOTEK Network Camera IB8369/FD8164/FD816BA; most others have similar firmware that may be affected. | 2 | 5 | Medium | 2017-07-18 | 2017-07-05 | View | |
87361 | CVE-2017-9828 | /cgi-bin/admin/testserver.cgi' of the web service in most of the VIVOTEK Network Cameras is vulnerable to shell command injection, which allows remote attackers to execute any shell command as root via a crafted HTTP request. This vulnerability is already verified on VIVOTEK Network Camera IB8369/FD8164/FD816BA; most others have similar firmware that may be affected. An attack uses shell metacharacters in the senderemail parameter. | 2 | 10 | High | 2017-07-18 | 2017-07-05 | View | |
87408 | CVE-2017-9833 | /cgi-bin/wapopen in BOA Webserver 0.94.14rc21 allows the injection of ../.. using the FILECAMERA variable (sent by GET) to read files with root privileges. | 2 | 5 | Medium | 2017-07-18 | 2017-07-03 | View | |
79186 | CVE-2002-0172 | /dev/ipfilter on SGI IRIX 6.5 is installed by /dev/MAKEDEV with insecure default permissions (644), which could allow a local user to cause a denial of service (traffic disruption). | 2 | 2.1 | Low | 2017-01-05 | 2008-09-10 | View | |
7525 | CVE-2011-0461 | /etc/init.d/boot.localfs in the aaa_base package before 11.2-43.48.1 in SUSE openSUSE 11.2, and before 11.3-8.7.1 in openSUSE 11.3, allows local users to overwrite arbitrary files via a symlink attack on /dev/shm/mtab. | 2 | 6.3 | Medium | 2017-01-07 | 2014-02-20 | View |
Page 322 of 17672, showing 5 records out of 88360 total, starting on record 1606, ending on 1610