NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
86451 | CVE-2017-0896 | Zulip Server 1.5.1 and below suffer from an error in the implementation of the invite_by_admins_only setting in the Zulip group chat application server that allowed an authenticated user to invite other users to join a Zulip organization even if the organization was configured to prevent this. | 2 | 4 | Medium | 2017-06-17 | 2017-06-13 | View | |
85801 | CVE-2017-0895 | Nextcloud Server before 10.0.4 and 11.0.2 are vulnerable to disclosure of calendar and addressbook names to other logged-in users. Note that no actual content of the calendar and addressbook has been disclosed. | 2 | 3.5 | Low | 2017-05-27 | 2017-05-18 | View | |
85800 | CVE-2017-0894 | Nextcloud Server before 11.0.3 is vulnerable to disclosure of valid share tokens for public calendars due to a logical error. Thus granting an attacker potentially access to publicly shared calendars without knowing the share token. | 2 | 4.3 | Medium | 2017-05-27 | 2017-05-17 | View | |
85799 | CVE-2017-0893 | Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are shipping a vulnerable JavaScript library for sanitizing untrusted user-input which suffered from a XSS vulnerability caused by a behaviour change in Safari 10.1 and 10.2. Note that Nextcloud employs a strict Content-Security-Policy preventing exploitation of this XSS issue on modern web browsers. | 2 | 3.5 | Low | 2017-05-27 | 2017-05-18 | View | |
85798 | CVE-2017-0892 | Nextcloud Server before 11.0.3 is vulnerable to an improper session handling allowed an application specific password without permission to the files access to the users file. | 2 | 4.3 | Medium | 2017-05-27 | 2017-05-17 | View |
Page 859 of 17672, showing 5 records out of 88360 total, starting on record 4291, ending on 4295