NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
85118  CVE-2016-1221  Jetstar App for iOS before 3.0.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.          2017-04-27  2017-04-21  View
84863  CVE-2017-7570  PivotX 2.3.11 allows remote authenticated Advanced users to execute arbitrary PHP code by performing an upload with a safe file extension (such as .jpg) and then invoking the duplicate function to change to the .php extension.    6.5  Medium  2017-04-27  2017-04-13  View
85119  CVE-2016-1518  The auto-provisioning mechanism in the Grandstream Wave app 1.0.1.26 and earlier for Android and Grandstream Video IP phones allows man-in-the-middle attackers to spoof provisioning data and consequently modify device functionality, obtain sensitive information from system logs, and have unspecified other impact by leveraging failure to use an HTTPS session for downloading configuration files from http://fm.grandstream.com/gs/.          2017-04-27  2017-04-21  View
83840  CVE-2017-7243  Eclipse tinydtls 0.8.2 for Eclipse IoT allows remote attackers to cause a denial of service (DTLS peer crash) by sending a Change cipher spec packet without pre-handshake.    Medium  2017-04-27  2017-03-30  View
84864  CVE-2017-7571  public/rolechangeadmin in Faveo 1.9.3 allows CSRF. The impact is obtaining admin privileges.    Medium  2017-04-27  2017-04-12  View

Page 15862 of 17672, showing 5 records out of 88360 total, starting on record 79306, ending on 79310

Actions