NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
85281  CVE-2016-1178  The session management of the comment functionality in appleple a-blog cms 2.6.0.1 and earlier allows remote attackers to obtain or modify sensitive data via unspecified vectors.    6.4  Medium  2017-04-27  2017-04-20  View
84770  CVE-2017-7192  WebSocket.swift in Starscream before 2.0.4 allows an SSL Pinning bypass because of incorrect management of the certValidated variable (it can be set to true but cannot be set to false).    Medium  2017-04-27  2017-04-24  View
85282  CVE-2016-1179  Cross-site scripting (XSS) vulnerability in the standard template of the comment functionality in appleple a-blog cms 2.6.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML.    4.3  Medium  2017-04-27  2017-04-20  View
85283  CVE-2016-1713  Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetailsSave.php in Vtiger CRM 6.4.0 allows remote authenticated users to execute arbitrary code by uploading a crafted image file with an executable extension, then accessing it via a direct request to the file in test/logo/. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-6000.    8.5  High  2017-04-27  2017-04-25  View
83748  CVE-2017-5899  Directory traversal vulnerability in the setuid root helper binary in S-nail (later S-mailx) before 14.8.16 allows local users to write to arbitrary files and consequently gain root privileges via a .. (dot dot) in the randstr argument.    6.9  Medium  2017-04-27  2017-03-31  View

Page 1760 of 17672, showing 5 records out of 88360 total, starting on record 8796, ending on 8800

Actions