关键字 的搜索结果 (14248)

CVE-2016-4311(发布:2017-02-16 21:59:11)NMP
CVSS6.8

[原文]Cross-site request forgery (CSRF) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 allows remote attackers to hijack the authentication of privileged users for requests that process XACML requests via an entitlement/eval-policy-submit.jsp request.

CVE-2016-4312(发布:2017-02-16 21:59:11)NMPS
CVSS6.0

[原文]XML external entity (XXE) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 before WSO2-CARBON-PATCH-4.4.0-0231 allows remote authenticated users with access to XACML features to read arbitrary files, cause a denial of service, conduct server-side request forgery (SSRF) attacks, or have unspecified other impact via a crafted XACML request to entitlement/eval-policy-submit.jsp. NOTE: this issue can be combined with CVE-2016-4311 to exploit the vulnerability without credentials.

CVE-2015-6023(发布:2017-02-09 10:59:00)NMPS
CVSS7.5

[原文]ping.cgi in NetCommWireless HSPA 3G10WVE wireless routers with firmware before 3G10WVE-L101-S306ETS-C01_R05 allows remote attackers to bypass intended access restrictions via a direct request. NOTE: this issue can be combined with CVE-2015-6024 to execute arbitrary commands.

CVE-2015-6024(发布:2017-02-09 10:59:00)NMP
CVSS10.0

[原文]ping.cgi in NetCommWireless HSPA 3G10WVE wireless routers with firmware before 3G10WVE-L101-S306ETS-C01_R05 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the DIA_IPADDRESS parameter.

CVE-2016-3053(发布:2017-02-01 15:59:00)NMPS
CVSS7.2

[原文]IBM AIX contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privileges.

CVE-2016-1417(发布:2017-01-23 16:59:01)NMPS
CVSS6.8

[原文]Untrusted search path vulnerability in Snort 2.9.7.0-WIN32 allows remote attackers to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse tcapi.dll that is located in the same folder on a remote file share as a pcap file that is being processed.

首页上一页23456789下一页尾页 第4页 / 共2375页

关于SCAP中文社区

SCAP中文社区是国内第一个以SCAP为主题的中文开放社区。了解更多信息,请查阅[关于本站]

版权声明

CVE/CWE/OVAL均为MITRE公司的注册商标,它们的官方数据源均保存在MITRE公司的相关网站