CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
93006 | CVE-2016-6186 | Candidate | Cross-site scripting (XSS) vulnerability in the dismissChangeRelatedObjectPopup function in contrib/admin/static/admin/js/admin/RelatedObjectLookups.js in Django before 1.8.14, 1.9.x before 1.9.8, and 1.10.x before 1.10rc1 allows remote attackers to inject arbitrary web script or HTML via vectors involving unsafe usage of Element.innerHTML. | Assigned (20160708) | None (candidate not yet proposed) | View | |
93007 | CVE-2016-6187 | Candidate | The apparmor_setprocattr function in security/apparmor/lsm.c in the Linux kernel before 4.6.5 does not validate the buffer size, which allows local users to gain privileges by triggering an AppArmor setprocattr hook. | Assigned (20160709) | None (candidate not yet proposed) | View | |
93008 | CVE-2016-6188 | Candidate | Memory leak in SOGo 2.3.7 allows remote attackers to cause a denial of service (memory consumption) via a large number of attempts to upload a large attachment, related to temporary files. | Assigned (20160709) | None (candidate not yet proposed) | View | |
93009 | CVE-2016-6189 | Candidate | Incomplete blacklist in SOGo before 2.3.12 and 3.x before 3.1.1 allows remote authenticated users to obtain sensitive information by reading the fields in the (1) ics or (2) XML calendar feeds. | Assigned (20160709) | None (candidate not yet proposed) | View | |
93010 | CVE-2016-6190 | Candidate | SOGo before 2.3.12 and 3.x before 3.1.1 does not restrict access to the UID and DTSTAMP attributes, which allows remote authenticated users to obtain sensitive information about appointments with the "View the Date & Time" restriction, as demonstrated by correlating UIDs and DTSTAMPs between all users. | Assigned (20160709) | None (candidate not yet proposed) | View |
Page 18602 of 20943, showing 5 records out of 104715 total, starting on record 93006, ending on 93010