CVE List

Id CVE No. Status Description Phase Votes Comments Actions
96254  CVE-2016-9434  Candidate  An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. w3m allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted HTML page.  Assigned (20161118)  None (candidate not yet proposed)    View
96255  CVE-2016-9435  Candidate  The HTMLtagproc1 function in file.c in w3m before 0.5.3+git20161009 does not properly initialize values, which allows remote attackers to crash the application via a crafted html file, related to <dd> tags.  Assigned (20161118)  None (candidate not yet proposed)    View
96274  CVE-2016-9454  Candidate  Revive Adserver before 3.2.3 suffers from Persistent XSS. A vector for persistent XSS attacks via the Revive Adserver user interface exists, requiring a trusted (non-admin) account. The banner image URL for external banners wasn"t properly escaped when displayed in most of the banner related pages.  Assigned (20161119)  None (candidate not yet proposed)    View
96275  CVE-2016-9455  Candidate  Revive Adserver before 3.2.3 suffers from Cross-Site Request Forgery (CSRF). A number of scripts in Revive Adserver"s user interface are vulnerable to CSRF attacks: `www/admin/banner-acl.php`, `www/admin/banner-activate.php`, `www/admin/banner-advanced.php`, `www/admin/banner-modify.php`, `www/admin/banner-swf.php`, `www/admin/banner-zone.php`, `www/admin/tracker-modify.php`.  Assigned (20161119)  None (candidate not yet proposed)    View
96276  CVE-2016-9456  Candidate  Revive Adserver before 3.2.3 suffers from Cross-Site Request Forgery (CSRF). The Revive Adserver team conducted a security audit of the admin interface scripts in order to identify and fix other potential CSRF vulnerabilities. Over 20+ such issues were fixed.  Assigned (20161119)  None (candidate not yet proposed)    View

Page 18649 of 20943, showing 5 records out of 104715 total, starting on record 93241, ending on 93245

Actions