Show filters
545 Total Results
Displaying 411-420 of 545
Sort by:
Attacker Value
Unknown

CVE-2017-1000086

Disclosure Date: October 05, 2017 (last updated November 26, 2024)
The Periodic Backup Plugin did not perform any permission checks, allowing any user with Overall/Read access to change its settings, trigger backups, restore backups, download backups, and also delete all previous backups via log rotation. Additionally, the plugin was not requiring requests to its API be sent via POST, thereby opening itself to Cross-Site Request Forgery attacks.
0
Attacker Value
Unknown

CVE-2017-11615

Disclosure Date: July 26, 2017 (last updated November 26, 2024)
A sandbox escape in the Lua interface in Wube Factorio before 0.15.31 allows remote game servers or user-assisted attackers to execute arbitrary C code by including and loading a C library.
0
Attacker Value
Unknown

CVE-2017-11445

Disclosure Date: July 19, 2017 (last updated November 26, 2024)
Subrion CMS before 4.1.6 has a SQL injection vulnerability in /front/actions.php via the $_POST array.
0
Attacker Value
Unknown

CVE-2017-11444

Disclosure Date: July 19, 2017 (last updated November 26, 2024)
Subrion CMS before 4.1.5.10 has a SQL injection vulnerability in /front/search.php via the $_GET array.
0
Attacker Value
Unknown

CVE-2017-10795

Disclosure Date: July 02, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in Subrion CMS 4.1.4 allows remote attackers to inject arbitrary web script or HTML via the body to blog/add/, a different vulnerability than CVE-2017-6069.
0
Attacker Value
Unknown

CVE-2017-7440

Disclosure Date: May 02, 2017 (last updated January 27, 2024)
Kerio Connect 8.0.0 through 9.2.2, and Kerio Connect Client desktop application for Windows and Mac 9.2.0 through 9.2.2, when e-mail preview is enabled, allows remote attackers to conduct clickjacking attacks via a crafted e-mail message.
Attacker Value
Unknown

CVE-2017-8289

Disclosure Date: April 27, 2017 (last updated November 26, 2024)
Stack-based buffer overflow in the ipv6_addr_from_str function in sys/net/network_layer/ipv6/addr/ipv6_addr_from_str.c in RIOT prior to 2017-04-25 allows local attackers, and potentially remote attackers, to cause a denial of service or possibly have unspecified other impact via a malformed IPv6 address.
0
Attacker Value
Unknown

CVE-2017-7306

Disclosure Date: April 04, 2017 (last updated November 08, 2023)
Riverbed RiOS through 9.6.0 has a weak default password for the secure vault, which makes it easier for physically proximate attackers to defeat the secure-vault protection mechanism by leveraging knowledge of the password algorithm and the appliance serial number. NOTE: the vendor believes that this does not meet the definition of a vulnerability. The product contains correct computational logic for supporting arbitrary password changes by customers; however, a password change is optional to meet different customers' needs
0
Attacker Value
Unknown

CVE-2017-5670

Disclosure Date: April 04, 2017 (last updated November 26, 2024)
Riverbed RiOS through 9.6.0 deletes the secure vault with the rm program (not shred or srm), which makes it easier for physically proximate attackers to obtain sensitive information by reading raw disk blocks.
0
Attacker Value
Unknown

CVE-2017-7307

Disclosure Date: April 04, 2017 (last updated November 26, 2024)
Riverbed RiOS before 9.0.1 does not properly restrict shell access in single-user mode, which makes it easier for physically proximate attackers to obtain root privileges and access decrypted data by replacing the /opt/tms/bin/cli file.
0