CVE List

Id CVE No. Status Description Phase Votes Comments Actions
93106  CVE-2016-6286  Candidate  The "spiffy-cgi-handlers" egg would convert a nonexistent "Proxy" header to the HTTP_PROXY environment variable, which would allow attackers to direct CGI programs which use this environment variable to use an attacker-specified HTTP proxy server (also known as a "httpoxy" attack). This affects all versions of spiffy-cgi-handlers before 0.5.  Assigned (20160722)  None (candidate not yet proposed)    View
93107  CVE-2016-6287  Candidate  The "http-client" egg always used a HTTP_PROXY environment variable to determine whether HTTP traffic should be routed via a proxy, even when running as a CGI process. Under several web servers this would mean a user-supplied "Proxy" header could allow an attacker to direct all HTTP requests through a proxy (also known as a "httpoxy" attack). This affects all versions of http-client before 0.10.  Assigned (20160722)  None (candidate not yet proposed)    View
93108  CVE-2016-6288  Candidate  The php_url_parse_ex function in ext/standard/url.c in PHP before 5.5.38 allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via vectors involving the smart_str data type.  Assigned (20160724)  None (candidate not yet proposed)    View
93109  CVE-2016-6289  Candidate  Integer overflow in the virtual_file_ex function in TSRM/tsrm_virtual_cwd.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact via a crafted extract operation on a ZIP archive.  Assigned (20160724)  None (candidate not yet proposed)    View
93110  CVE-2016-6290  Candidate  ext/session/session.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 does not properly maintain a certain hash data structure, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via vectors related to session deserialization.  Assigned (20160724)  None (candidate not yet proposed)    View

Page 18622 of 20943, showing 5 records out of 104715 total, starting on record 93106, ending on 93110

Actions