CVE List

Id CVE No. Status Description Phase Votes Comments Actions
96271  CVE-2016-9451  Candidate  Confirmation forms in Drupal 7.x before 7.52 make it easier for remote authenticated users to conduct open redirect attacks via unspecified vectors.  Assigned (20161118)  None (candidate not yet proposed)    View
96272  CVE-2016-9452  Candidate  The transliterate mechanism in Drupal 8.x before 8.2.3 allows remote attackers to cause a denial of service via a crafted URL.  Assigned (20161118)  None (candidate not yet proposed)    View
96273  CVE-2016-9453  Candidate  The t2p_readwrite_pdf_image_tile function in LibTIFF allows remote attackers to cause a denial of service (out-of-bounds write and crash) or possibly execute arbitrary code via a JPEG file with a TIFFTAG_JPEGTABLES of length one.  Assigned (20161118)  None (candidate not yet proposed)    View
96242  CVE-2016-9422  Candidate  An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. The feed_table_tag function in w3m doesn"t properly validate the value of table span, which allows remote attackers to cause a denial of service (stack and/or heap buffer overflow) and possibly execute arbitrary code via a crafted HTML page.  Assigned (20161118)  None (candidate not yet proposed)    View
96243  CVE-2016-9423  Candidate  An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Heap-based buffer overflow in w3m allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted HTML page.  Assigned (20161118)  None (candidate not yet proposed)    View

Page 18646 of 20943, showing 5 records out of 104715 total, starting on record 93226, ending on 93230

Actions