NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
86205 | CVE-2017-9083 | poppler 0.54.0, as used in Evince and other products, has a NULL pointer dereference in the JPXStream::readUByte function in JPXStream.cc. For example, the perf_test utility will crash (segmentation fault) when parsing an invalid PDF file. | 2 | 4.3 | Medium | 2017-06-03 | 2017-05-31 | View | |
86204 | CVE-2017-9080 | PlaySMS 1.4 allows remote code execution because PHP code in the name of an uploaded .php file is executed. sendfromfile.php has a combination of Unrestricted File Upload and Code Injection. | 2 | 7.5 | High | 2017-06-03 | 2017-06-01 | View | |
86203 | CVE-2017-9079 | Dropbear before 2017.75 might allow local users to read certain files as root, if the file has the authorized_keys file format with a command= option. This occurs because ~/.ssh/authorized_keys is read with root privileges and symlinks are followed. | 2 | 4.7 | Medium | 2017-05-27 | 2017-05-24 | View | |
86202 | CVE-2017-9078 | The server in Dropbear before 2017.75 might allow post-authentication root remote code execution because of a double free in cleanup of TCP listeners when the -a option is enabled. | 2 | 9.3 | High | 2017-05-27 | 2017-05-24 | View | |
86201 | CVE-2017-9077 | The tcp_v6_syn_recv_sock function in net/ipv6/tcp_ipv6.c in the Linux kernel through 4.11.1 mishandles inheritance, which allows local users to cause a denial of service or possibly have unspecified other impact via crafted system calls, a related issue to CVE-2017-8890. | 2 | 7.2 | High | 2017-06-03 | 2017-05-31 | View |
Page 432 of 17672, showing 5 records out of 88360 total, starting on record 2156, ending on 2160