NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
86111 | CVE-2017-8877 | ASUS RT-AC* and RT-N* devices with firmware through 3.0.0.4.380.7378 allow JSONP Information Disclosure such as the SSID. | 2 | 4 | Medium | 2017-05-27 | 2017-05-16 | View | |
85600 | CVE-2017-8793 | An issue was discovered on Accellion FTA devices before FTA_9_12_180. By sending a POST request to home/seos/courier/web/wmProgressstat.html.php with an attacker domain in the acallow parameter, the device will respond with an Access-Control-Allow-Origin header allowing the attacker to have site access with a bypass of the Same Origin Policy. | 2 | 6.8 | Medium | 2017-05-27 | 2017-05-17 | View | |
86112 | CVE-2017-8878 | ASUS RT-AC* and RT-N* devices with firmware before 3.0.0.4.380.7378 allow remote authenticated users to discover the Wi-Fi password via WPS_info.xml. | 2 | 4 | Medium | 2017-05-27 | 2017-05-16 | View | |
85345 | CVE-2016-7051 | XmlMapper in the Jackson XML dataformat component (aka jackson-dataformat-xml) before 2.7.8 and 2.8.x before 2.8.4 allows remote attackers to conduct server-side request forgery (SSRF) attacks via vectors related to a DTD. | 2 | 5 | Medium | 2017-05-27 | 2017-05-25 | View | |
85601 | CVE-2017-8794 | An issue was discovered on Accellion FTA devices before FTA_9_12_180. Because a regular expression (intended to match local https URLs) lacks an initial ^ character, courier/web/1000@/wmProgressval.html allows SSRF attacks with a file:///etc/passwd#https:// URL pattern. | 2 | 6.4 | Medium | 2017-05-27 | 2017-05-17 | View |
Page 1628 of 17672, showing 5 records out of 88360 total, starting on record 8136, ending on 8140