NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
18705 | CVE-2016-2492 | The MediaTek power-management driver in Android before 2016-06-01 on Android One devices allows attackers to gain privileges via a crafted application, aka internal bug 28085410. | 2 | 9.3 | High | 2017-01-19 | 2016-06-16 | View | |
18961 | CVE-2016-3085 | Apache CloudStack 4.5.x before 4.5.2.1, 4.6.x before 4.6.2.1, 4.7.x before 4.7.1.1, and 4.8.x before 4.8.0.1, when SAML-based authentication is enabled and used, allow remote attackers to bypass authentication and access the user interface via vectors related to the SAML plugin. | 2 | 5.8 | Medium | 2017-01-19 | 2016-06-14 | View | |
19217 | CVE-2016-3409 | Cross-site scripting (XSS) vulnerability in Zimbra Collaboration before 8.7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka bug 102637. | 2 | 4.3 | Medium | 2017-02-06 | 2017-02-01 | View | |
19473 | CVE-2016-3703 | Red Hat OpenShift Enterprise 3.2 and 3.1 do not properly validate the origin of a request when anonymous access is granted to a service/proxy or pod/proxy API for a specific pod, which allows remote attackers to access API credentials in the web browser localStorage via an access_token in the query parameter. | 2 | 3.5 | Low | 2017-01-19 | 2016-06-09 | View | |
19729 | CVE-2016-4003 | Cross-site scripting (XSS) vulnerability in the URLDecoder function in JRE before 1.8, as used in Apache Struts 2.x before 2.3.28, when using a single byte page encoding, allows remote attackers to inject arbitrary web script or HTML via multi-byte characters in a url-encoded parameter. | 2 | 4.3 | Medium | 2017-01-19 | 2016-11-28 | View |
Page 1043 of 17672, showing 5 records out of 88360 total, starting on record 5211, ending on 5215