NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
86432 | CVE-2016-3403 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Admin Console in Zimbra Collaboration before 8.6.0 Patch 8 allow remote attackers to hijack the authentication of administrators for requests that (1) add, (2) modify, or (3) remove accounts by leveraging failure to use of a CSRF token and perform referer header checks, aka bugs 100885 and 100899. | 2 | 6.8 | Medium | 2017-06-04 | 2017-05-30 | View | |
86688 | CVE-2017-9442 | ** DISPUTED ** BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary code by uploading a crafted package containing a PHP web shell, related to extraction of a ZIP archive to filename patterns such as cache/package/xxx/yyy.php. This issue exists in coreadminmodulesdeveloperextensionsinstallunpack.php and coreadminmodulesdeveloperpackagesinstallunpack.php. NOTE: the vendor states You must implicitly trust any package or extension you install as they all have the ability to write PHP files. | 2 | 6.5 | Medium | 2017-06-12 | 2017-06-09 | View | |
86944 | CVE-2017-5697 | Insufficient clickjacking protection in the Web User Interface of Intel AMT firmware versions before 9.1.40.1000, 9.5.60.1952, 10.0.50.1004, 11.0.0.1205, and 11.6.25.1129 potentially allowing a remote attacker to hijack users web clicks via attacker's crafted web page. | 2 | 4.3 | Medium | 2017-06-28 | 2017-06-27 | View | |
87200 | CVE-2016-10335 | In all Android releases from CAF using the Linux kernel, libtomcrypt was updated. | 2 | 4.3 | Medium | 2017-06-23 | 2017-06-19 | View | |
87456 | CVE-2015-2245 | Huawei Ascend P7 allows remote attackers to cause a denial of service (phone process crash). | 2017-06-28 | 2017-06-27 | View |
Page 1464 of 17672, showing 5 records out of 88360 total, starting on record 7316, ending on 7320