Show filters
545 Total Results
Displaying 411-420 of 545
Sort by:
Attacker Value
Unknown
CVE-2017-1000086
Disclosure Date: October 05, 2017 (last updated November 26, 2024)
The Periodic Backup Plugin did not perform any permission checks, allowing any user with Overall/Read access to change its settings, trigger backups, restore backups, download backups, and also delete all previous backups via log rotation. Additionally, the plugin was not requiring requests to its API be sent via POST, thereby opening itself to Cross-Site Request Forgery attacks.
0
Attacker Value
Unknown
CVE-2017-11615
Disclosure Date: July 26, 2017 (last updated November 26, 2024)
A sandbox escape in the Lua interface in Wube Factorio before 0.15.31 allows remote game servers or user-assisted attackers to execute arbitrary C code by including and loading a C library.
0
Attacker Value
Unknown
CVE-2017-11445
Disclosure Date: July 19, 2017 (last updated November 26, 2024)
Subrion CMS before 4.1.6 has a SQL injection vulnerability in /front/actions.php via the $_POST array.
0
Attacker Value
Unknown
CVE-2017-11444
Disclosure Date: July 19, 2017 (last updated November 26, 2024)
Subrion CMS before 4.1.5.10 has a SQL injection vulnerability in /front/search.php via the $_GET array.
0
Attacker Value
Unknown
CVE-2017-10795
Disclosure Date: July 02, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in Subrion CMS 4.1.4 allows remote attackers to inject arbitrary web script or HTML via the body to blog/add/, a different vulnerability than CVE-2017-6069.
0
Attacker Value
Unknown
CVE-2017-7440
Disclosure Date: May 02, 2017 (last updated January 27, 2024)
Kerio Connect 8.0.0 through 9.2.2, and Kerio Connect Client desktop application for Windows and Mac 9.2.0 through 9.2.2, when e-mail preview is enabled, allows remote attackers to conduct clickjacking attacks via a crafted e-mail message.
0
Attacker Value
Unknown
CVE-2017-8289
Disclosure Date: April 27, 2017 (last updated November 26, 2024)
Stack-based buffer overflow in the ipv6_addr_from_str function in sys/net/network_layer/ipv6/addr/ipv6_addr_from_str.c in RIOT prior to 2017-04-25 allows local attackers, and potentially remote attackers, to cause a denial of service or possibly have unspecified other impact via a malformed IPv6 address.
0
Attacker Value
Unknown
CVE-2017-7306
Disclosure Date: April 04, 2017 (last updated November 08, 2023)
Riverbed RiOS through 9.6.0 has a weak default password for the secure vault, which makes it easier for physically proximate attackers to defeat the secure-vault protection mechanism by leveraging knowledge of the password algorithm and the appliance serial number. NOTE: the vendor believes that this does not meet the definition of a vulnerability. The product contains correct computational logic for supporting arbitrary password changes by customers; however, a password change is optional to meet different customers' needs
0
Attacker Value
Unknown
CVE-2017-5670
Disclosure Date: April 04, 2017 (last updated November 26, 2024)
Riverbed RiOS through 9.6.0 deletes the secure vault with the rm program (not shred or srm), which makes it easier for physically proximate attackers to obtain sensitive information by reading raw disk blocks.
0
Attacker Value
Unknown
CVE-2017-7307
Disclosure Date: April 04, 2017 (last updated November 26, 2024)
Riverbed RiOS before 9.0.1 does not properly restrict shell access in single-user mode, which makes it easier for physically proximate attackers to obtain root privileges and access decrypted data by replacing the /opt/tms/bin/cli file.
0