NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
85502 | CVE-2017-8059 | Acceptance of invalid/self-signed TLS certificates in Foxit PDF - PDF reader, editor, form, signature before 5.4 for iOS allows a man-in-the-middle and/or physically proximate attacker to silently intercept login information (username/password), in addition to the static authentication token if the user is already logged in. | 2 | 4.3 | Medium | 2017-05-27 | 2017-05-17 | View | |
85501 | CVE-2017-8058 | Acceptance of invalid/self-signed TLS certificates in Atlassian HipChat before 3.16.2 for iOS allows a man-in-the-middle and/or physically proximate attacker to silently intercept information sent during the login API call. | 2 | 4.3 | Medium | 2017-05-27 | 2017-05-16 | View | |
85022 | CVE-2017-8057 | In Joomla! 3.4.0 through 3.6.5 (fixed in 3.7.0), multiple files caused full path disclosures on systems with enabled error reporting. | 2 | 5 | Medium | 2017-05-07 | 2017-05-03 | View | |
85021 | CVE-2017-8056 | WatchGuard Fireware v11.12.1 and earlier mishandles requests referring to an XML External Entity (XXE), in the XML-RPC agent. This causes the Firebox wgagent process to crash. This process crash ends all authenticated sessions to the Firebox, including management connections, and prevents new authenticated sessions until the process has recovered. The Firebox may also experience an overall degradation in performance while the wgagent process recovers. An attacker could continuously send XML-RPC requests that contain references to external entities to perform a limited Denial of Service (DoS) attack against an affected Firebox. | 2 | 5 | Medium | 2017-05-07 | 2017-04-27 | View | |
85020 | CVE-2017-8055 | WatchGuard Fireware allows user enumeration, e.g., in the Firebox XML-RPC login handler. A login request that contains a blank password sent to the XML-RPC agent in Fireware v11.12.1 and earlier returns different responses for valid and invalid usernames. An attacker could exploit this vulnerability to enumerate valid usernames on an affected Firebox. | 2 | 5 | Medium | 2017-05-07 | 2017-04-27 | View |
Page 202 of 17672, showing 5 records out of 88360 total, starting on record 1006, ending on 1010