CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
102445 | CVE-2017-5625 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20170129) | None (candidate not yet proposed) | View | |
102444 | CVE-2017-5624 | Candidate | An issue was discovered in OxygenOS before 4.0.3 for OnePlus 3 and 3T. The attacker can persistently make the (locked) bootloader start the platform with dm-verity disabled, by issuing the "fastboot oem disable_dm_verity" command. Having dm-verity disabled, the kernel will not verify the system partition (and any other dm-verity protected partition), which may allow for persistent code execution and privilege escalation. | Assigned (20170129) | None (candidate not yet proposed) | View | |
102443 | CVE-2017-5623 | Candidate | An issue was discovered in OxygenOS before 4.1.0 on OnePlus 3 and 3T devices. The attacker can change the bootmode of the device by issuing the "fastboot oem boot_mode {rf/wlan/ftm/normal} command" in contradiction to the threat model of Android where the bootloader MUST NOT allow any security-sensitive operation to be run unless the bootloader is unlocked. | Assigned (20170129) | None (candidate not yet proposed) | View | |
102442 | CVE-2017-5622 | Candidate | With OxygenOS before 4.0.3, when a charger is connected to a powered-off OnePlus 3 or 3T device, the platform starts with adbd enabled. Therefore, a malicious charger or a physical attacker can open up, without authorization, an ADB session with the device, in order to further exploit other vulnerabilities and/or exfiltrate sensitive information. | Assigned (20170129) | None (candidate not yet proposed) | View | |
102441 | CVE-2017-5621 | Candidate | An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. XSS can be triggered via malicious HTML in a chat message or the content of a ticket article, when using either the REST API or the WebSocket API. | Assigned (20170129) | None (candidate not yet proposed) | View |
Page 455 of 20943, showing 5 records out of 104715 total, starting on record 2271, ending on 2275