NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 85118 | CVE-2016-1221 | Jetstar App for iOS before 3.0.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | 2017-04-27 | 2017-04-21 | View | ||||
| 84863 | CVE-2017-7570 | PivotX 2.3.11 allows remote authenticated Advanced users to execute arbitrary PHP code by performing an upload with a safe file extension (such as .jpg) and then invoking the duplicate function to change to the .php extension. | 2 | 6.5 | Medium | 2017-04-27 | 2017-04-13 | View | |
| 85119 | CVE-2016-1518 | The auto-provisioning mechanism in the Grandstream Wave app 1.0.1.26 and earlier for Android and Grandstream Video IP phones allows man-in-the-middle attackers to spoof provisioning data and consequently modify device functionality, obtain sensitive information from system logs, and have unspecified other impact by leveraging failure to use an HTTPS session for downloading configuration files from http://fm.grandstream.com/gs/. | 2017-04-27 | 2017-04-21 | View | ||||
| 83840 | CVE-2017-7243 | Eclipse tinydtls 0.8.2 for Eclipse IoT allows remote attackers to cause a denial of service (DTLS peer crash) by sending a Change cipher spec packet without pre-handshake. | 2 | 5 | Medium | 2017-04-27 | 2017-03-30 | View | |
| 84864 | CVE-2017-7571 | public/rolechangeadmin in Faveo 1.9.3 allows CSRF. The impact is obtaining admin privileges. | 2 | 6 | Medium | 2017-04-27 | 2017-04-12 | View |
Page 15862 of 17672, showing 5 records out of 88360 total, starting on record 79306, ending on 79310