NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
86426 | CVE-2016-10296 | An information disclosure vulnerability in the Qualcomm shared memory driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-33845464. References: QC-CR#1109782. | 2 | 2.6 | Low | 2017-05-27 | 2017-05-19 | View | |
86427 | CVE-2016-10329 | Command injection vulnerability in login.php in Synology Photo Station before 6.5.3-3226 allows remote attackers to execute arbitrary code via shell metacharacters in the crafted 'X-Forwarded-For' header. | 2 | 7.5 | High | 2017-05-27 | 2017-05-23 | View | |
86428 | CVE-2016-10330 | Directory traversal vulnerability in synophoto_dsm_user, a SUID program, as used in Synology Photo Station before 6.5.3-3226 allows local users to write to arbitrary files via unspecified vectors. | 2 | 4.6 | Medium | 2017-05-27 | 2017-05-23 | View | |
86429 | CVE-2016-10331 | Directory traversal vulnerability in download.php in Synology Photo Station before 6.5.3-3226 allows remote attackers to read arbitrary files via a full pathname in the id parameter. | 2 | 5 | Medium | 2017-05-27 | 2017-05-23 | View | |
86430 | CVE-2016-10370 | An issue was discovered on OnePlus devices such as the 3T. The OnePlus OTA Updater pushes the signed-OTA image over HTTP without TLS. While it does not allow for installation of arbitrary OTAs (due to the digital signature), it unnecessarily increases the attack surface, and allows for remote exploitation of other vulnerabilities such as CVE-2017-5948, CVE-2017-8850, and CVE-2017-8851. | 2 | 5 | Medium | 2017-05-27 | 2017-05-22 | View |
Page 17286 of 17672, showing 5 records out of 88360 total, starting on record 86426, ending on 86430