CVE List

Id CVE No. Status Description Phase Votes Comments Actions
93006  CVE-2016-6186  Candidate  Cross-site scripting (XSS) vulnerability in the dismissChangeRelatedObjectPopup function in contrib/admin/static/admin/js/admin/RelatedObjectLookups.js in Django before 1.8.14, 1.9.x before 1.9.8, and 1.10.x before 1.10rc1 allows remote attackers to inject arbitrary web script or HTML via vectors involving unsafe usage of Element.innerHTML.  Assigned (20160708)  None (candidate not yet proposed)    View
93007  CVE-2016-6187  Candidate  The apparmor_setprocattr function in security/apparmor/lsm.c in the Linux kernel before 4.6.5 does not validate the buffer size, which allows local users to gain privileges by triggering an AppArmor setprocattr hook.  Assigned (20160709)  None (candidate not yet proposed)    View
93008  CVE-2016-6188  Candidate  Memory leak in SOGo 2.3.7 allows remote attackers to cause a denial of service (memory consumption) via a large number of attempts to upload a large attachment, related to temporary files.  Assigned (20160709)  None (candidate not yet proposed)    View
93009  CVE-2016-6189  Candidate  Incomplete blacklist in SOGo before 2.3.12 and 3.x before 3.1.1 allows remote authenticated users to obtain sensitive information by reading the fields in the (1) ics or (2) XML calendar feeds.  Assigned (20160709)  None (candidate not yet proposed)    View
93010  CVE-2016-6190  Candidate  SOGo before 2.3.12 and 3.x before 3.1.1 does not restrict access to the UID and DTSTAMP attributes, which allows remote authenticated users to obtain sensitive information about appointments with the "View the Date & Time" restriction, as demonstrated by correlating UIDs and DTSTAMPs between all users.  Assigned (20160709)  None (candidate not yet proposed)    View

Page 18602 of 20943, showing 5 records out of 104715 total, starting on record 93006, ending on 93010

Actions