CVE List

Id CVE No. Status Description Phase Votes Comments Actions
102439  CVE-2017-5619  Candidate  An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. Attackers can login with the hashed password itself (e.g., from the DB) instead of the valid password string.  Assigned (20170129)  None (candidate not yet proposed)    View
102440  CVE-2017-5620  Candidate  An XSS issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. Attachments are opened in a new tab instead of getting downloaded. This creates an attack vector of executing code in the domain of the application.  Assigned (20170129)  None (candidate not yet proposed)    View
102441  CVE-2017-5621  Candidate  An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. XSS can be triggered via malicious HTML in a chat message or the content of a ticket article, when using either the REST API or the WebSocket API.  Assigned (20170129)  None (candidate not yet proposed)    View
102442  CVE-2017-5622  Candidate  With OxygenOS before 4.0.3, when a charger is connected to a powered-off OnePlus 3 or 3T device, the platform starts with adbd enabled. Therefore, a malicious charger or a physical attacker can open up, without authorization, an ADB session with the device, in order to further exploit other vulnerabilities and/or exfiltrate sensitive information.  Assigned (20170129)  None (candidate not yet proposed)    View
102443  CVE-2017-5623  Candidate  An issue was discovered in OxygenOS before 4.1.0 on OnePlus 3 and 3T devices. The attacker can change the bootmode of the device by issuing the "fastboot oem boot_mode {rf/wlan/ftm/normal} command" in contradiction to the threat model of Android where the bootloader MUST NOT allow any security-sensitive operation to be run unless the bootloader is unlocked.  Assigned (20170129)  None (candidate not yet proposed)    View

Page 1075 of 20943, showing 5 records out of 104715 total, starting on record 5371, ending on 5375

Actions