CVE List

Id CVE No. Status Description Phase Votes Comments Actions
93941  CVE-2016-7121  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20160902)  None (candidate not yet proposed)    View
93942  CVE-2016-7122  Candidate  The avi_read_nikon function in libavformat/avidec.c in FFmpeg before 3.1.4 is vulnerable to infinite loop when it decodes an AVI file that has a crafted "nctg" structure.  Assigned (20160902)  None (candidate not yet proposed)    View
93943  CVE-2016-7123  Candidate  Cross-site request forgery (CSRF) vulnerability in the admin web interface in GNU Mailman before 2.1.15 allows remote attackers to hijack the authentication of administrators.  Assigned (20160902)  None (candidate not yet proposed)    View
93944  CVE-2016-7124  Candidate  ext/standard/var_unserializer.c in PHP before 5.6.25 and 7.x before 7.0.10 mishandles certain invalid objects, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted serialized data that leads to a (1) __destruct call or (2) magic method call.  Assigned (20160902)  None (candidate not yet proposed)    View
93945  CVE-2016-7125  Candidate  ext/session/session.c in PHP before 5.6.25 and 7.x before 7.0.10 skips invalid session names in a way that triggers incorrect parsing, which allows remote attackers to inject arbitrary-type session data by leveraging control of a session name, as demonstrated by object injection.  Assigned (20160902)  None (candidate not yet proposed)    View

Page 18789 of 20943, showing 5 records out of 104715 total, starting on record 93941, ending on 93945

Actions