NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
48070  CVE-2009-0751  Yaws before 1.80 allows remote attackers to cause a denial of service (memory consumption and crash) via a request with a large number of headers.    Medium  2017-01-07  2010-04-27  View
87751  CVE-2017-10974  Yaws 1.91 allows Unauthenticated Remote File Disclosure via HTTP Directory Traversal with /%5C../ to port 8080. NOTE: this CVE is only about use of an initial /%5C sequence to defeat traversal protection mechanisms; the initial /%5C sequence was apparently not discussed in earlier research on this product.    Medium  2017-07-18  2017-07-14  View
51617  CVE-2009-4495  Yaws 1.85 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window"s title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator.    Medium  2017-01-07  2012-02-29  View
17954  CVE-2016-1601  yast2-users before 3.1.47, as used in SUSE Linux Enterprise 12 SP1, does not properly set empty password fields in /etc/shadow during an AutoYaST installation when the profile does not contain inst-sys users, which might allow attackers to have unspecified impact via unknown vectors.    10  High  2017-01-19  2016-11-30  View
4450  CVE-2008-4636  yast2-backup 2.14.2 through 2.16.6 on SUSE Linux and Novell Linux allows local users to gain privileges via shell metacharacters in filenames used by the backup process.    7.2  High  2017-01-03  2008-12-03  View

Page 44 of 17672, showing 5 records out of 88360 total, starting on record 216, ending on 220

Actions