NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
87282 | CVE-2017-3218 | Samsung Magician 5.0 fails to validate TLS certificates for HTTPS software update traffic. Prior to version 5.0, Samsung Magician uses HTTP for software updates. | 2 | 8.3 | High | 2017-07-18 | 2017-07-03 | View | |
87281 | CVE-2017-3216 | WiMAX routers based on the MediaTek SDK (libmtk) that use a custom httpd plugin are vulnerable to an authentication bypass allowing a remote, unauthenticated attacker to gain administrator access to the device by performing an administrator password change on the device via a crafted POST request. | 2 | 10 | High | 2017-07-18 | 2017-07-06 | View | |
87280 | CVE-2017-3215 | The Milwaukee ONE-KEY Android mobile application uses bearer tokens with an expiration of one year. This bearer token, in combination with a user_id can be used to perform user actions. | 2 | 5 | Medium | 2017-07-18 | 2017-07-05 | View | |
87279 | CVE-2017-3214 | The Milwaukee ONE-KEY Android mobile application stores the master token in plaintext in the apk binary. | 2 | 5 | Medium | 2017-07-18 | 2017-07-05 | View | |
85431 | CVE-2017-3213 | The Think Mutual Bank Mobile Banking app 3.1.5 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | 2 | 4.3 | Medium | 2017-05-27 | 2017-05-15 | View |
Page 633 of 17672, showing 5 records out of 88360 total, starting on record 3161, ending on 3165