NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
83232 | CVE-2017-5638 | The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 mishandles file upload, which allows remote attackers to execute arbitrary commands via a #cmd= string in a crafted Content-Type HTTP header, as exploited in the wild in March 2017. | 2 | 10 | High | 2017-07-18 | 2017-07-17 | View | |
82241 | CVE-2017-5634 | The Norwegian Air Shuttle (aka norwegian.com) airline kiosk allows physically proximate attackers to bypass the intended Please select booking identification UI step, and obtain administrative privileges and network access on the underlying Windows OS, by accessing a touch-screen print icon to manipulate the print dialog. | 2 | 7.2 | High | 2017-03-18 | 2017-02-28 | View | |
83231 | CVE-2017-5633 | Multiple cross-site request forgery (CSRF) vulnerabilities on the D-Link DI-524 Wireless Router with firmware 9.01 allow remote attackers to (1) change the admin password, (2) reboot the device, or (3) possibly have unspecified other impact via crafted requests to CGI programs. | 2 | 8.5 | High | 2017-03-18 | 2017-03-09 | View | |
81680 | CVE-2017-5632 | An issue was discovered on the ASUS RT-N56U Wireless Router with Firmware 3.0.0.4.374_979. When executing an nmap -O command that specifies an IP address of an affected device, one can crash the device's WAN connection, causing disconnection from the Internet, a Denial of Service (DoS). The attack is only possible from within the local area network. | 2 | 3.3 | Low | 2017-03-18 | 2017-03-09 | View | |
85442 | CVE-2017-5631 | An issue was discovered in KMCIS CaseAware. Reflected cross site scripting is present in the user parameter (i.e., usr) that is transmitted in the login.php query string. | 2 | 4.3 | Medium | 2017-05-27 | 2017-05-15 | View |
Page 456 of 17672, showing 5 records out of 88360 total, starting on record 2276, ending on 2280