NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
84770  CVE-2017-7192  WebSocket.swift in Starscream before 2.0.4 allows an SSL Pinning bypass because of incorrect management of the certValidated variable (it can be set to true but cannot be set to false).    Medium  2017-04-27  2017-04-24  View
84786  CVE-2017-7282  An issue was discovered in Unitrends Enterprise Backup before 9.1.1. The function downloadFile in api/includes/restore.php blindly accepts any filename passed to /api/restore/download as valid. This allows an authenticated attacker to read any file in the filesystem that the web server has access to, aka Local File Inclusion (LFI).    7.1  High  2017-04-27  2017-04-24  View
84787  CVE-2017-7283  An authenticated user of Unitrends Enterprise Backup before 9.1.2 can execute arbitrary OS commands by sending a specially crafted filename to the /api/restore/download-files endpoint, related to the downloadFiles function in api/includes/restore.php.    High  2017-04-27  2017-04-24  View
22344  CVE-2016-9278  The Samsung Exynos fimg2d driver for Android with Exynos 5433, 54xx, or 7420 chipsets allows local users to cause a denial of service (kernel panic) via a crafted ioctl command. The Samsung ID is SVE-2016-6736.    4.9  Medium  2017-04-27  2017-04-24  View
22345  CVE-2016-9279  Use-after-free vulnerability in the Samsung Exynos fimg2d driver for Android with Exynos 5433, 54xx, or 7420 chipsets allows attackers to obtain sensitive information via unspecified vectors. The Samsung ID is SVE-2016-6853.    Medium  2017-04-27  2017-04-24  View

Page 1776 of 17672, showing 5 records out of 88360 total, starting on record 8876, ending on 8880

Actions