NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
85065  CVE-2017-8284  ** DISPUTED ** The disas_insn function in target/i386/translate.c in QEMU before 2.9.0, when TCG mode without hardware acceleration is used, does not limit the instruction size, which allows local users to gain privileges by creating a modified basic block that injects code into a setuid program, as demonstrated by procmail. NOTE: the vendor has stated this bug does not violate any security guarantees QEMU makes.    6.9  Medium  2017-05-27  2017-05-10  View
85064  CVE-2017-8283  dpkg-source in dpkg 1.3.0 through 1.18.23 is able to use a non-GNU patch program and does not offer a protection mechanism for blank-indented diff hunks, which allows remote attackers to conduct directory traversal attacks via a crafted Debian source package, as demonstrated by use of dpkg-source on NetBSD.    7.5  High  2017-05-27  2017-05-10  View
85063  CVE-2017-8225  On Wireless IP Camera (P2P) WIFICAM devices, access to .ini files (containing credentials) is not correctly checked. An attacker can bypass authentication by providing an empty loginuse parameter and an empty loginpas parameter in the URI.    7.5  High  2017-05-07  2017-05-05  View
85062  CVE-2017-8224  Wireless IP Camera (P2P) WIFICAM devices have a backdoor root account that can be accessed with TELNET.    10  High  2017-05-07  2017-05-05  View
85061  CVE-2017-8223  On Wireless IP Camera (P2P) WIFICAM devices, an attacker can use the RTSP server on port 10554/tcp to watch the streaming without authentication via tcp/av0_1 or tcp/av0_0.    Medium  2017-05-07  2017-05-05  View

Page 660 of 17672, showing 5 records out of 88360 total, starting on record 3296, ending on 3300

Actions