NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
85940 | CVE-2017-5948 | An issue was discovered on OnePlus One, X, 2, 3, and 3T devices. OxygenOS and HydrogenOS are vulnerable to downgrade attacks. This is due to a lenient 'updater-script' in OTAs that does not check that the current version is lower than or equal to the given image's. Downgrades can occur even on locked bootloaders and without triggering a factory reset, allowing for exploitation of now-patched vulnerabilities with access to user data. This vulnerability can be exploited by a Man-in-the-Middle (MiTM) attacker targeting the update process. This is possible because the update transaction does not occur over TLS (CVE-2016-10370). In addition, a physical attacker can reboot the phone into recovery, and then use 'adb sideload' to push the OTA (on OnePlus 3/3T 'Secure Start-up' must be off). | 2 | 4.3 | Medium | 2017-05-27 | 2017-05-19 | View | |
86196 | CVE-2017-9072 | Two CalendarXP products have XSS in common parts of HTML files. CalendarXP FlatCalendarXP through 9.9.290 has XSS in iflateng.htm and nflateng.htm. CalendarXP PopCalendarXP through 9.8.308 has XSS in ipopeng.htm and npopeng.htm. | 2 | 4.3 | Medium | 2017-05-27 | 2017-05-26 | View | |
86452 | CVE-2017-2300 | On Juniper Networks SRX Series Services Gateways chassis clusters running Junos OS 12.1X46 prior to 12.1X46-D65, 12.3X48 prior to 12.3X48-D40, 12.3X48 prior to 12.3X48-D60, flowd daemon on the primary node of an SRX Series chassis cluster may crash and restart when attempting to synchronize a multicast session created via crafted multicast packets. | 2 | 5 | Medium | 2017-06-12 | 2017-06-09 | View | |
86708 | CVE-2017-9516 | Craft CMS before 2.6.2982 allows for a potential XSS attack vector by uploading a malicious SVG file. | 2 | 3.5 | Low | 2017-06-17 | 2017-06-14 | View | |
86964 | CVE-2017-6687 | A vulnerability in Cisco Ultra Services Framework Element Manager could allow an authenticated, remote attacker with access to the management network to log in to the affected device using default credentials present on the system, aka an Insecure Default Password Vulnerability. More Information: CSCvc76695. Known Affected Releases: 21.0.0. | 2 | 6.5 | Medium | 2017-06-23 | 2017-06-20 | View |
Page 16867 of 17672, showing 5 records out of 88360 total, starting on record 84331, ending on 84335