NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
84865 | CVE-2017-7572 | The _checkPolkitPrivilege function in serviceHelper.py in Back In Time (aka backintime) 1.1.18 and earlier uses a deprecated polkit authorization method (unix-process) that is subject to a race condition (time of check, time of use). With this authorization method, the owner of a process requesting a polkit operation is checked by polkitd via /proc/<pid>/status, by which time the requesting process may have been replaced by a different process with the same PID that has different privileges then the original requester. | 2 | 9.3 | High | 2017-04-27 | 2017-04-12 | View | |
84864 | CVE-2017-7571 | public/rolechangeadmin in Faveo 1.9.3 allows CSRF. The impact is obtaining admin privileges. | 2 | 6 | Medium | 2017-04-27 | 2017-04-12 | View | |
84863 | CVE-2017-7570 | PivotX 2.3.11 allows remote authenticated Advanced users to execute arbitrary PHP code by performing an upload with a safe file extension (such as .jpg) and then invoking the duplicate function to change to the .php extension. | 2 | 6.5 | Medium | 2017-04-27 | 2017-04-13 | View | |
84862 | CVE-2017-7569 | In vBulletin before 5.3.0, remote attackers can bypass the CVE-2016-6483 patch and conduct SSRF attacks by leveraging the behavior of the PHP parse_url function, aka VBV-17037. | 2 | 5 | Medium | 2017-04-27 | 2017-04-12 | View | |
84861 | CVE-2017-7566 | MyBB before 1.8.11 allows remote attackers to bypass an SSRF protection mechanism. | 2 | 4 | Medium | 2017-04-27 | 2017-04-13 | View |
Page 700 of 17672, showing 5 records out of 88360 total, starting on record 3496, ending on 3500