NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
85470 | CVE-2017-6564 | On Franklin Fueling Systems TS-550 evo 2.3.0.7332 devices, the Guest user, which contains the lowest privileges, can post to the idSourceFileName parameter found within the /download directory. This ability allows for an attacker to download sensitive system files from the host machine such as databases which contain information that can aid in further attacks. | 2 | 4 | Medium | 2017-05-27 | 2017-05-12 | View | |
85469 | CVE-2017-6557 | SQL injection vulnerability in ArrayOS before AG 9.4.0.135, when the portal bookmark function is enabled, allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | 2 | 6.5 | Medium | 2017-05-27 | 2017-05-17 | View | |
85468 | CVE-2017-6553 | Buffer Overflow in Quest One Identity Privilege Manager for Unix before 6.0.0.061 allows remote attackers to obtain full access to the policy server via an ACT_ALERT_EVENT request that causes memory corruption in the pmmasterd daemon. | 2 | 10 | High | 2017-05-27 | 2017-05-11 | View | |
85467 | CVE-2017-6551 | Pexip Infinity before 14.2 allows remote attackers to cause a denial of service (service restart) or execute arbitrary code via vectors related to Conferencing Nodes. | 2 | 7.5 | High | 2017-05-27 | 2017-05-12 | View | |
85466 | CVE-2017-6520 | The Multicast DNS (mDNS) responder used in BOSE Soundtouch 30 inadvertently responds to IPv4 unicast queries with source addresses that are not link-local, which allows remote attackers to cause a denial of service (traffic amplification) or obtain potentially sensitive information via port-5353 UDP packets. | 2 | 6.4 | Medium | 2017-05-27 | 2017-05-16 | View |
Page 579 of 17672, showing 5 records out of 88360 total, starting on record 2891, ending on 2895