NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
85120 | CVE-2016-1519 | The com.softphone.common package in the Grandstream Wave app 1.0.1.26 and earlier for Android does not properly validate SSL certificates, which allows man-in-the-middle attackers to spoof the Grandstream provisioning server via a crafted certificate. | 2017-04-27 | 2017-04-21 | View | ||||
85119 | CVE-2016-1518 | The auto-provisioning mechanism in the Grandstream Wave app 1.0.1.26 and earlier for Android and Grandstream Video IP phones allows man-in-the-middle attackers to spoof provisioning data and consequently modify device functionality, obtain sensitive information from system logs, and have unspecified other impact by leveraging failure to use an HTTPS session for downloading configuration files from http://fm.grandstream.com/gs/. | 2017-04-27 | 2017-04-21 | View | ||||
85118 | CVE-2016-1221 | Jetstar App for iOS before 3.0.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | 2017-04-27 | 2017-04-21 | View | ||||
85117 | CVE-2016-1220 | Cybozu Garoon before 4.2.2 does not properly restrict access. | 2 | 4 | Medium | 2017-04-27 | 2017-04-25 | View | |
85116 | CVE-2016-1219 | Cybozu Garoon before 4.2.2 allows remote attackers to bypass login authentication via vectors related to API use. | 2 | 7.5 | High | 2017-04-27 | 2017-04-25 | View |
Page 649 of 17672, showing 5 records out of 88360 total, starting on record 3241, ending on 3245