NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
84916  CVE-2017-7628  The Smart related articles extension 1.1 for Joomla! has SQL injection in dialog.php (attacker must use search_cats variable in POST method to exploit this vulnerability).    7.5  High  2017-04-27  2017-04-20  View
85428  CVE-2017-3008  Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a reflected cross-site scripting vulnerability.    4.3  Medium  2017-07-18  2017-07-10  View
85684  CVE-2017-0231  A spoofing vulnerability exists when Microsoft browsers render SmartScreen Filter, aka Microsoft Browser Spoofing Vulnerability.    4.3  Medium  2017-07-18  2017-07-07  View
85940  CVE-2017-5948  An issue was discovered on OnePlus One, X, 2, 3, and 3T devices. OxygenOS and HydrogenOS are vulnerable to downgrade attacks. This is due to a lenient 'updater-script' in OTAs that does not check that the current version is lower than or equal to the given image's. Downgrades can occur even on locked bootloaders and without triggering a factory reset, allowing for exploitation of now-patched vulnerabilities with access to user data. This vulnerability can be exploited by a Man-in-the-Middle (MiTM) attacker targeting the update process. This is possible because the update transaction does not occur over TLS (CVE-2016-10370). In addition, a physical attacker can reboot the phone into recovery, and then use 'adb sideload' to push the OTA (on OnePlus 3/3T 'Secure Start-up' must be off).    4.3  Medium  2017-05-27  2017-05-19  View
86196  CVE-2017-9072  Two CalendarXP products have XSS in common parts of HTML files. CalendarXP FlatCalendarXP through 9.9.290 has XSS in iflateng.htm and nflateng.htm. CalendarXP PopCalendarXP through 9.8.308 has XSS in ipopeng.htm and npopeng.htm.    4.3  Medium  2017-05-27  2017-05-26  View

Page 1618 of 17672, showing 5 records out of 88360 total, starting on record 8086, ending on 8090

Actions