NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
87788 | CVE-2017-11127 | Bolt CMS 3.2.14 allows stored XSS by uploading an SVG document with a Content-Type: image/svg+xml header. | 2017-07-18 | 2017-07-17 | View | ||||
87789 | CVE-2017-11128 | Bolt CMS 3.2.14 allows stored XSS via text input, as demonstrated by the Title field of a New Entry. | 2017-07-18 | 2017-07-17 | View | ||||
88301 | CVE-2016-0764 | Race condition in Network Manager before 1.0.12 as packaged in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Workstation 7 allows local users to obtain sensitive connection information by reading temporary files during ifcfg and keyfile changes. | 2017-07-18 | 2017-07-17 | View | ||||
88302 | CVE-2016-10397 | In PHP before 5.6.28 and 7.x before 7.0.13, incorrect handling of various URI components in the URL parser could be used by attackers to bypass hostname-specific URL checks, as demonstrated by evil.example.com:80#@good.example.com/ and evil.example.com:80?@good.example.com/ inputs to the parse_url function (implemented in the php_url_parse_ex function in ext/standard/url.c). | 2 | 5 | Medium | 2017-07-18 | 2017-07-17 | View | |
88303 | CVE-2016-10398 | Android 6.0 has an authentication bypass for attackers with root and physical access. Cryptographic authentication tokens (AuthTokens) used by the Trusted Execution Environment (TEE) are protected by a weak challenge. This allows adversaries to replay previously captured responses and use the TEE without authenticating. All apps using authentication-gated cryptography are vulnerable to this attack, which was confirmed on the LG Nexus 5X. | 2017-07-18 | 2017-07-17 | View |
Page 17658 of 17672, showing 5 records out of 88360 total, starting on record 88286, ending on 88290