NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
87788  CVE-2017-11127  Bolt CMS 3.2.14 allows stored XSS by uploading an SVG document with a Content-Type: image/svg+xml header.          2017-07-18  2017-07-17  View
87789  CVE-2017-11128  Bolt CMS 3.2.14 allows stored XSS via text input, as demonstrated by the Title field of a New Entry.          2017-07-18  2017-07-17  View
88301  CVE-2016-0764  Race condition in Network Manager before 1.0.12 as packaged in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Workstation 7 allows local users to obtain sensitive connection information by reading temporary files during ifcfg and keyfile changes.          2017-07-18  2017-07-17  View
88302  CVE-2016-10397  In PHP before 5.6.28 and 7.x before 7.0.13, incorrect handling of various URI components in the URL parser could be used by attackers to bypass hostname-specific URL checks, as demonstrated by evil.example.com:80#@good.example.com/ and evil.example.com:80?@good.example.com/ inputs to the parse_url function (implemented in the php_url_parse_ex function in ext/standard/url.c).    Medium  2017-07-18  2017-07-17  View
88303  CVE-2016-10398  Android 6.0 has an authentication bypass for attackers with root and physical access. Cryptographic authentication tokens (AuthTokens) used by the Trusted Execution Environment (TEE) are protected by a weak challenge. This allows adversaries to replay previously captured responses and use the TEE without authenticating. All apps using authentication-gated cryptography are vulnerable to this attack, which was confirmed on the LG Nexus 5X.          2017-07-18  2017-07-17  View

Page 17658 of 17672, showing 5 records out of 88360 total, starting on record 88286, ending on 88290

Actions