NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
84770 | CVE-2017-7192 | WebSocket.swift in Starscream before 2.0.4 allows an SSL Pinning bypass because of incorrect management of the certValidated variable (it can be set to true but cannot be set to false). | 2 | 5 | Medium | 2017-04-27 | 2017-04-24 | View | |
84769 | CVE-2017-7188 | Zurmo 3.1.1 Stable allows a Cross-Site Scripting (XSS) attack with a base64-encoded SCRIPT element within a data: URL in the returnUrl parameter to default/toggleCollapse. | 2 | 3.5 | Low | 2017-04-27 | 2017-04-21 | View | |
84768 | CVE-2017-7185 | Use-after-free vulnerability in the mg_http_multipart_wait_for_boundary function in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.7 and earlier and Mongoose OS 1.2 and earlier allows remote attackers to cause a denial of service (crash) via a multipart/form-data POST request without a MIME boundary string. | 2 | 5 | Medium | 2017-04-27 | 2017-04-14 | View | |
84767 | CVE-2017-6975 | Wi-Fi in Apple iOS before 10.3.1 does not prevent CVE-2017-6956 stack buffer overflow exploitation via a crafted access point. NOTE: because an operating system could potentially isolate itself from CVE-2017-6956 exploitation without patching Broadcom firmware functions, there is a separate CVE ID for the operating-system behavior. | 2 | 7.2 | High | 2017-07-18 | 2017-07-11 | View | |
84766 | CVE-2017-6974 | An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the system-installation subsystem of the System Integrity Protection component. It allows attackers to modify the contents of a protected disk location via a crafted app. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-11 | View |
Page 719 of 17672, showing 5 records out of 88360 total, starting on record 3591, ending on 3595