NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
83495  CVE-2017-6918  CSRF exists in BigTree CMS 4.2.16 with the value[#][*] parameter to the admin/settings/update/ page. The Navigation Social can be changed.    4.3  Medium  2017-03-18  2017-03-16  View
83751  CVE-2017-5932  The path autocompletion feature in Bash 4.4 allows local users to gain privileges via a crafted filename starting with a (double quote) character and a command substitution metacharacter.    4.6  Medium  2017-04-27  2017-03-31  View
84263  CVE-2017-2385  An issue was discovered in certain Apple products. Safari before 10.1 is affected. The issue involves the Safari Login AutoFill component. It allows local users to obtain access to locked keychain items via unspecified vectors.    2.1  Low  2017-07-18  2017-07-11  View
84519  CVE-2017-3507  Vulnerability in the Oracle Service Bus component of Oracle Fusion Middleware (subcomponent: Web Console Design). Supported versions that are affected are 12.1.3.0.0, 12.2.1.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Service Bus. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Service Bus accessible data as well as unauthorized read access to a subset of Oracle Service Bus accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Service Bus. CVSS 3.0 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).    7.5  High  2017-07-18  2017-07-10  View
84775  CVE-2017-7221  OpenText Documentum Content Server has an inadequate protection mechanism against SQL injection, which allows remote authenticated users to execute arbitrary code with super-user privileges by leveraging the availability of the dm_bp_transition docbase method with a user-created dm_procedure object, as demonstrated by use of a backspace character in an injected string. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2513.    6.5  Medium  2017-05-07  2017-05-05  View

Page 552 of 17672, showing 5 records out of 88360 total, starting on record 2756, ending on 2760

Actions