NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
84770  CVE-2017-7192  WebSocket.swift in Starscream before 2.0.4 allows an SSL Pinning bypass because of incorrect management of the certValidated variable (it can be set to true but cannot be set to false).    Medium  2017-04-27  2017-04-24  View
84769  CVE-2017-7188  Zurmo 3.1.1 Stable allows a Cross-Site Scripting (XSS) attack with a base64-encoded SCRIPT element within a data: URL in the returnUrl parameter to default/toggleCollapse.    3.5  Low  2017-04-27  2017-04-21  View
84768  CVE-2017-7185  Use-after-free vulnerability in the mg_http_multipart_wait_for_boundary function in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.7 and earlier and Mongoose OS 1.2 and earlier allows remote attackers to cause a denial of service (crash) via a multipart/form-data POST request without a MIME boundary string.    Medium  2017-04-27  2017-04-14  View
84767  CVE-2017-6975  Wi-Fi in Apple iOS before 10.3.1 does not prevent CVE-2017-6956 stack buffer overflow exploitation via a crafted access point. NOTE: because an operating system could potentially isolate itself from CVE-2017-6956 exploitation without patching Broadcom firmware functions, there is a separate CVE ID for the operating-system behavior.    7.2  High  2017-07-18  2017-07-11  View
84766  CVE-2017-6974  An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the system-installation subsystem of the System Integrity Protection component. It allows attackers to modify the contents of a protected disk location via a crafted app.    4.3  Medium  2017-07-18  2017-07-11  View

Page 719 of 17672, showing 5 records out of 88360 total, starting on record 3591, ending on 3595

Actions