NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
85001 | CVE-2017-7978 | Samsung Android devices with L(5.0/5.1), M(6.0), and N(7.x) software allow attackers to obtain sensitive information by reading a world-readable log file after an unexpected reboot. The Samsung ID is SVE-2017-8290. | 2 | 5 | Medium | 2017-04-27 | 2017-04-24 | View | |
85278 | CVE-2016-10345 | In Phusion Passenger before 5.1.0, a known /tmp filename was used during passenger-install-nginx-module execution, which could allow local attackers to gain the privileges of the passenger user. | 2 | 4.6 | Medium | 2017-04-27 | 2017-04-24 | View | |
85280 | CVE-2016-1155 | HTTP header injection vulnerability in the URLConnection class in Android OS 2.2 through 6.0 allows remote attackers to execute arbitrary scripts or set arbitrary values in cookies. | 2 | 7.5 | High | 2017-04-27 | 2017-04-24 | View | |
84770 | CVE-2017-7192 | WebSocket.swift in Starscream before 2.0.4 allows an SSL Pinning bypass because of incorrect management of the certValidated variable (it can be set to true but cannot be set to false). | 2 | 5 | Medium | 2017-04-27 | 2017-04-24 | View | |
84786 | CVE-2017-7282 | An issue was discovered in Unitrends Enterprise Backup before 9.1.1. The function downloadFile in api/includes/restore.php blindly accepts any filename passed to /api/restore/download as valid. This allows an authenticated attacker to read any file in the filesystem that the web server has access to, aka Local File Inclusion (LFI). | 2 | 7.1 | High | 2017-04-27 | 2017-04-24 | View |
Page 15889 of 17672, showing 5 records out of 88360 total, starting on record 79441, ending on 79445