NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
84770 | CVE-2017-7192 | WebSocket.swift in Starscream before 2.0.4 allows an SSL Pinning bypass because of incorrect management of the certValidated variable (it can be set to true but cannot be set to false). | 2 | 5 | Medium | 2017-04-27 | 2017-04-24 | View | |
84786 | CVE-2017-7282 | An issue was discovered in Unitrends Enterprise Backup before 9.1.1. The function downloadFile in api/includes/restore.php blindly accepts any filename passed to /api/restore/download as valid. This allows an authenticated attacker to read any file in the filesystem that the web server has access to, aka Local File Inclusion (LFI). | 2 | 7.1 | High | 2017-04-27 | 2017-04-24 | View | |
84787 | CVE-2017-7283 | An authenticated user of Unitrends Enterprise Backup before 9.1.2 can execute arbitrary OS commands by sending a specially crafted filename to the /api/restore/download-files endpoint, related to the downloadFiles function in api/includes/restore.php. | 2 | 9 | High | 2017-04-27 | 2017-04-24 | View | |
22344 | CVE-2016-9278 | The Samsung Exynos fimg2d driver for Android with Exynos 5433, 54xx, or 7420 chipsets allows local users to cause a denial of service (kernel panic) via a crafted ioctl command. The Samsung ID is SVE-2016-6736. | 2 | 4.9 | Medium | 2017-04-27 | 2017-04-24 | View | |
22345 | CVE-2016-9279 | Use-after-free vulnerability in the Samsung Exynos fimg2d driver for Android with Exynos 5433, 54xx, or 7420 chipsets allows attackers to obtain sensitive information via unspecified vectors. The Samsung ID is SVE-2016-6853. | 2 | 5 | Medium | 2017-04-27 | 2017-04-24 | View |
Page 1776 of 17672, showing 5 records out of 88360 total, starting on record 8876, ending on 8880