NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
84778  CVE-2017-7234  A maliciously crafted URL to a Django (1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18) site using the ``django.views.static.serve()`` view could redirect to any other domain, aka an open redirect vulnerability.    5.8  Medium  2017-07-18  2017-07-11  View
19498  CVE-2016-3738  Red Hat OpenShift Enterprise 3.2 does not properly restrict access to STI builds, which allows remote authenticated users to access the Docker socket and gain privileges via vectors related to build-pod.    6.5  Medium  2017-01-19  2016-06-09  View
85034  CVE-2017-8072  The cp2112_gpio_direction_input function in drivers/hid/hid-cp2112.c in the Linux kernel 4.9.x before 4.9.9 does not have the expected EIO error status for a zero-length report, which allows local users to have an unspecified impact via unknown vectors.    7.2  High  2017-05-07  2017-04-27  View
19754  CVE-2016-4046  An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev11. The API to configure external mail accounts can be abused to map and access network components within the trust boundary of the operator. Users can inject arbitrary hosts and ports to API calls. Depending on the response type, content and latency, information about existence of hosts and services can be gathered. Attackers can get internal configuration information about the infrastructure of an operator to prepare subsequent attacks.    Medium  2017-01-19  2016-12-16  View
85290  CVE-2016-2566  Samsung SecEmailSync on SM-G920F build G920FXXU2COH2 (Galaxy S6) devices has SQL injection, aka SVE-2015-5081.    7.5  High  2017-04-27  2017-04-21  View

Page 2881 of 17672, showing 5 records out of 88360 total, starting on record 14401, ending on 14405

Actions