NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
83501 | CVE-2017-6958 | An XSS vulnerability in the MantisBT Source Integration Plugin (before 2.0.2) search result page allows an attacker to inject arbitrary HTML or JavaScript (if MantisBT's CSP settings permit it) by crafting any valid parameter. | 2 | 4.3 | Medium | 2017-03-29 | 2017-03-20 | View | |
84269 | CVE-2017-2391 | An issue was discovered in certain Apple products. Pages before 6.1, Numbers before 4.1, and Keynote before 7.1 on macOS and Pages before 3.1, Numbers before 3.1, and Keynote before 3.1 on iOS are affected. The issue involves the Export component. It allows users to bypass iWork PDF password protection by leveraging use of 40-bit RC4. | 2 | 5 | Medium | 2017-07-18 | 2017-07-11 | View | |
84525 | CVE-2017-3513 | Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.0.38 and Prior to 5.1.20. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.0 Base Score 2.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N). | 2 | 1.9 | Low | 2017-07-18 | 2017-07-10 | View | |
84781 | CVE-2017-7241 | A cross-site scripting (XSS) vulnerability in the MantisBT Move Attachments page (move_attachments_page.php, part of admin tools) allows remote attackers to inject arbitrary code through a crafted 'type' parameter, if Content Security Protection (CSP) settings allows it. This is fixed in 1.3.9, 2.1.3, and 2.2.3. Note that this vulnerability is not exploitable if the admin tools directory is removed, as recommended in the Post-installation and upgrade tasks of the MantisBT Admin Guide. A reminder to do so is also displayed on the login page. | 2 | 3.5 | Low | 2017-07-18 | 2017-07-11 | View | |
85037 | CVE-2017-8075 | On the TP-Link TL-SG108E 1.0, a remote attacker could retrieve credentials from Switch Info log lines where passwords are in cleartext. This affects the 1.1.2 Build 20141017 Rel.50749 firmware. | 2 | 5 | Medium | 2017-05-07 | 2017-04-27 | View |
Page 15850 of 17672, showing 5 records out of 88360 total, starting on record 79246, ending on 79250