NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 84778 | CVE-2017-7234 | A maliciously crafted URL to a Django (1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18) site using the ``django.views.static.serve()`` view could redirect to any other domain, aka an open redirect vulnerability. | 2 | 5.8 | Medium | 2017-07-18 | 2017-07-11 | View | |
| 19498 | CVE-2016-3738 | Red Hat OpenShift Enterprise 3.2 does not properly restrict access to STI builds, which allows remote authenticated users to access the Docker socket and gain privileges via vectors related to build-pod. | 2 | 6.5 | Medium | 2017-01-19 | 2016-06-09 | View | |
| 85034 | CVE-2017-8072 | The cp2112_gpio_direction_input function in drivers/hid/hid-cp2112.c in the Linux kernel 4.9.x before 4.9.9 does not have the expected EIO error status for a zero-length report, which allows local users to have an unspecified impact via unknown vectors. | 2 | 7.2 | High | 2017-05-07 | 2017-04-27 | View | |
| 19754 | CVE-2016-4046 | An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev11. The API to configure external mail accounts can be abused to map and access network components within the trust boundary of the operator. Users can inject arbitrary hosts and ports to API calls. Depending on the response type, content and latency, information about existence of hosts and services can be gathered. Attackers can get internal configuration information about the infrastructure of an operator to prepare subsequent attacks. | 2 | 5 | Medium | 2017-01-19 | 2016-12-16 | View | |
| 85290 | CVE-2016-2566 | Samsung SecEmailSync on SM-G920F build G920FXXU2COH2 (Galaxy S6) devices has SQL injection, aka SVE-2015-5081. | 2 | 7.5 | High | 2017-04-27 | 2017-04-21 | View |
Page 2881 of 17672, showing 5 records out of 88360 total, starting on record 14401, ending on 14405