CVE List

Id CVE No. Status Description Phase Votes Comments Actions
95960  CVE-2016-9140  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20161101)  None (candidate not yet proposed)    View
95959  CVE-2016-9139  Candidate  Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) 3.3.x before 3.3.16, 4.0.x before 4.0.19, and 5.0.x before 5.0.14 allows remote attackers to inject arbitrary web script or HTML via a crafted attachment.  Assigned (20161101)  None (candidate not yet proposed)    View
95958  CVE-2016-9138  Candidate  PHP through 5.6.27 and 7.x through 7.0.12 mishandles property modification during __wakeup processing, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted serialized data, as demonstrated by Exception::__toString with DateInterval::__wakeup.  Assigned (20161101)  None (candidate not yet proposed)    View
95957  CVE-2016-9137  Candidate  Use-after-free vulnerability in the CURLFile implementation in ext/curl/curl_file.c in PHP before 5.6.27 and 7.x before 7.0.12 allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted serialized data that is mishandled during __wakeup processing.  Assigned (20161101)  None (candidate not yet proposed)    View
95956  CVE-2016-9136  Candidate  Artifex Software, Inc. MuJS before a0ceaf5050faf419401fe1b83acfa950ec8a8a89 allows context-dependent attackers to obtain sensitive information by using the "crafted JavaScript" approach, related to a "Buffer Over-read" issue.  Assigned (20161031)  None (candidate not yet proposed)    View

Page 1752 of 20943, showing 5 records out of 104715 total, starting on record 8756, ending on 8760

Actions