NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
86436  CVE-2016-4856  Cross-site scripting vulnerability in Splunk Enterprise 6.3.x prior to 6.3.5 and Splunk Light 6.3.x prior to 6.3.5 allows attacker with administrator rights to inject arbitrary web script or HTML via unspecified vectors.    3.5  Low  2017-05-27  2017-05-19  View
86692  CVE-2017-9449  SQL injection vulnerability in BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary SQL commands via core/admin/modules/developer/modules/views/create.php. The attacker creates a crafted table name at admin/developer/modules/views/create/ and the injection is visible at admin/ajax/auto-modules/views/searchable-page/ or admin/modules_name.    6.5  Medium  2017-06-17  2017-06-12  View
86948  CVE-2017-6661  A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA) and Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device, aka Message Tracking XSS. More Information: CSCvd30805 CSCvd34861. Known Affected Releases: 10.0.0-203 10.1.0-049.    4.3  Medium  2017-07-18  2017-07-07  View
87204  CVE-2016-10339  In all Android releases from CAF using the Linux kernel, HLOS can overwite secure memory or read contents of the keystore.    5.8  Medium  2017-06-23  2017-06-19  View
87460  CVE-2015-3840  The MessageStatusReceiver service in the AndroidManifest.XML in Android 5.1.1 and earlier allows local users to alter sent/received statuses of SMS and MMS messages without the associated "WRITE_SMS" permission.          2017-06-28  2017-06-27  View

Page 1494 of 17672, showing 5 records out of 88360 total, starting on record 7466, ending on 7470

Actions