NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
87083 | CVE-2017-8907 | Atlassian Bamboo 5.x before 5.15.7 and 6.x before 6.0.1 did not correctly check if a user creating a deployment project had the edit permission and therefore the rights to do so. An attacker who can login to Bamboo as a user without the edit permission for deployment projects is able to use this vulnerability, provided there is an existing plan with a green build, to create a deployment project and execute arbitrary code on an available Bamboo Agent. By default a local agent is enabled; this means that code execution can occur on the system hosting Bamboo as the user running Bamboo. | 2 | 6.5 | Medium | 2017-07-18 | 2017-07-05 | View | |
87339 | CVE-2017-9781 | A cross site scripting (XSS) vulnerability exists in Check_MK versions 1.4.0x prior to 1.4.0p6, allowing an unauthenticated remote attacker to inject arbitrary HTML or JavaScript via the _username parameter when attempting authentication to webapi.py, which is returned unencoded with content type text/html. | 2 | 4.3 | Medium | 2017-07-18 | 2017-06-29 | View | |
87595 | CVE-2017-1000058 | Stored XSS in chevereto CMS before version 3.8.11 | 2017-07-18 | 2017-07-17 | View | ||||
87851 | CVE-2017-11361 | Inteno routers have a JUCI ACL misconfiguration that allows the user account to read files, write to files, and add root SSH keys via JSON commands to ubus. (Exploitation is sometimes easy because the user password might be user or might match the Wi-Fi key.) | 2017-07-18 | 2017-07-17 | View | ||||
88107 | CVE-2017-7902 | A Reusing a Nonce, Key Pair in Encryption issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 programmable-logic controllers 1763-L16AWA, Series A and B, Version 16.00 and prior versions; 1763-L16BBB, Series A and B, Version 16.00 and prior versions; 1763-L16BWA, Series A and B, Version 16.00 and prior versions; and 1763-L16DWD, Series A and B, Version 16.00 and prior versions and Allen-Bradley MicroLogix 1400 programmable logic controllers 1766-L32AWA, Series A and B, Version 16.00 and prior versions; 1766-L32BWA, Series A and B, Version 16.00 and prior versions; 1766-L32BWAA, Series A and B, Version 16.00 and prior versions; 1766-L32BXB, Series A and B, Version 16.00 and prior versions; 1766-L32BXBA, Series A and B, Version 16.00 and prior versions; and 1766-L32AWAA, Series A and B, Version 16.00 and prior versions. The affected product reuses nonces, which may allow an attacker to capture and replay a valid request until the nonce is changed. | 2 | 5 | Medium | 2017-07-18 | 2017-07-07 | View |
Page 588 of 17672, showing 5 records out of 88360 total, starting on record 2936, ending on 2940