NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
86432  CVE-2016-3403  Multiple cross-site request forgery (CSRF) vulnerabilities in the Admin Console in Zimbra Collaboration before 8.6.0 Patch 8 allow remote attackers to hijack the authentication of administrators for requests that (1) add, (2) modify, or (3) remove accounts by leveraging failure to use of a CSRF token and perform referer header checks, aka bugs 100885 and 100899.    6.8  Medium  2017-06-04  2017-05-30  View
86688  CVE-2017-9442  ** DISPUTED ** BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary code by uploading a crafted package containing a PHP web shell, related to extraction of a ZIP archive to filename patterns such as cache/package/xxx/yyy.php. This issue exists in coreadminmodulesdeveloperextensionsinstallunpack.php and coreadminmodulesdeveloperpackagesinstallunpack.php. NOTE: the vendor states You must implicitly trust any package or extension you install as they all have the ability to write PHP files.    6.5  Medium  2017-06-12  2017-06-09  View
86944  CVE-2017-5697  Insufficient clickjacking protection in the Web User Interface of Intel AMT firmware versions before 9.1.40.1000, 9.5.60.1952, 10.0.50.1004, 11.0.0.1205, and 11.6.25.1129 potentially allowing a remote attacker to hijack users web clicks via attacker's crafted web page.    4.3  Medium  2017-06-28  2017-06-27  View
87200  CVE-2016-10335  In all Android releases from CAF using the Linux kernel, libtomcrypt was updated.    4.3  Medium  2017-06-23  2017-06-19  View
87456  CVE-2015-2245  Huawei Ascend P7 allows remote attackers to cause a denial of service (phone process crash).          2017-06-28  2017-06-27  View

Page 1464 of 17672, showing 5 records out of 88360 total, starting on record 7316, ending on 7320

Actions