NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
83501  CVE-2017-6958  An XSS vulnerability in the MantisBT Source Integration Plugin (before 2.0.2) search result page allows an attacker to inject arbitrary HTML or JavaScript (if MantisBT's CSP settings permit it) by crafting any valid parameter.    4.3  Medium  2017-03-29  2017-03-20  View
84269  CVE-2017-2391  An issue was discovered in certain Apple products. Pages before 6.1, Numbers before 4.1, and Keynote before 7.1 on macOS and Pages before 3.1, Numbers before 3.1, and Keynote before 3.1 on iOS are affected. The issue involves the Export component. It allows users to bypass iWork PDF password protection by leveraging use of 40-bit RC4.    Medium  2017-07-18  2017-07-11  View
84525  CVE-2017-3513  Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.0.38 and Prior to 5.1.20. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.0 Base Score 2.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N).    1.9  Low  2017-07-18  2017-07-10  View
84781  CVE-2017-7241  A cross-site scripting (XSS) vulnerability in the MantisBT Move Attachments page (move_attachments_page.php, part of admin tools) allows remote attackers to inject arbitrary code through a crafted 'type' parameter, if Content Security Protection (CSP) settings allows it. This is fixed in 1.3.9, 2.1.3, and 2.2.3. Note that this vulnerability is not exploitable if the admin tools directory is removed, as recommended in the Post-installation and upgrade tasks of the MantisBT Admin Guide. A reminder to do so is also displayed on the login page.    3.5  Low  2017-07-18  2017-07-11  View
85037  CVE-2017-8075  On the TP-Link TL-SG108E 1.0, a remote attacker could retrieve credentials from Switch Info log lines where passwords are in cleartext. This affects the 1.1.2 Build 20141017 Rel.50749 firmware.    Medium  2017-05-07  2017-04-27  View

Page 15850 of 17672, showing 5 records out of 88360 total, starting on record 79246, ending on 79250

Actions