NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
83232  CVE-2017-5638  The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 mishandles file upload, which allows remote attackers to execute arbitrary commands via a #cmd= string in a crafted Content-Type HTTP header, as exploited in the wild in March 2017.    10  High  2017-07-18  2017-07-17  View
82241  CVE-2017-5634  The Norwegian Air Shuttle (aka norwegian.com) airline kiosk allows physically proximate attackers to bypass the intended Please select booking identification UI step, and obtain administrative privileges and network access on the underlying Windows OS, by accessing a touch-screen print icon to manipulate the print dialog.    7.2  High  2017-03-18  2017-02-28  View
83231  CVE-2017-5633  Multiple cross-site request forgery (CSRF) vulnerabilities on the D-Link DI-524 Wireless Router with firmware 9.01 allow remote attackers to (1) change the admin password, (2) reboot the device, or (3) possibly have unspecified other impact via crafted requests to CGI programs.    8.5  High  2017-03-18  2017-03-09  View
81680  CVE-2017-5632  An issue was discovered on the ASUS RT-N56U Wireless Router with Firmware 3.0.0.4.374_979. When executing an nmap -O command that specifies an IP address of an affected device, one can crash the device's WAN connection, causing disconnection from the Internet, a Denial of Service (DoS). The attack is only possible from within the local area network.    3.3  Low  2017-03-18  2017-03-09  View
85442  CVE-2017-5631  An issue was discovered in KMCIS CaseAware. Reflected cross site scripting is present in the user parameter (i.e., usr) that is transmitted in the login.php query string.    4.3  Medium  2017-05-27  2017-05-15  View

Page 456 of 17672, showing 5 records out of 88360 total, starting on record 2276, ending on 2280

Actions