NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
84690  CVE-2017-5645  In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.    7.5  High  2017-04-27  2017-04-24  View
84689  CVE-2017-5642  During installation of Ambari 2.4.0 through 2.4.2, Ambari Server artifacts are not created with proper ACLs.    7.5  High  2017-04-27  2017-04-10  View
84688  CVE-2017-5625  In OxygenOS before 4.0.3 on OnePlus 3 and 3T devices, an unauthorized attacker can cause a locked bootloader to partially dump the ciphertext content of an arbitrary partition (except 'keystore') by issuing the 'fastboot oem dump <partition>' fastboot command.    2.1  Low  2017-05-07  2017-05-05  View
84687  CVE-2017-5607  Splunk Enterprise 5.0.x before 5.0.18, 6.0.x before 6.0.14, 6.1.x before 6.1.13, 6.2.x before 6.2.13.1, 6.3.x before 6.3.10, 6.4.x before 6.4.6, and 6.5.x before 6.5.3 and Splunk Light before 6.5.2 assigns the $C JS property to the global Window namespace, which might allow remote attackers to obtain sensitive logged-in username and version-related information via a crafted webpage.    4.3  Medium  2017-04-27  2017-04-17  View
84686  CVE-2017-5437  ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-10195, CVE-2016-10196, CVE-2016-10197. Reason: This candidate is a duplicate of CVE-2016-10195, CVE-2016-10196, and CVE-2016-10197. Notes: All CVE users should reference CVE-2016-10195, CVE-2016-10196, and/or CVE-2016-10197 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.        2017-04-27  2017-04-25  View

Page 735 of 17672, showing 5 records out of 88360 total, starting on record 3671, ending on 3675

Actions