CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
93941 | CVE-2016-7121 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20160902) | None (candidate not yet proposed) | View | |
93942 | CVE-2016-7122 | Candidate | The avi_read_nikon function in libavformat/avidec.c in FFmpeg before 3.1.4 is vulnerable to infinite loop when it decodes an AVI file that has a crafted "nctg" structure. | Assigned (20160902) | None (candidate not yet proposed) | View | |
93943 | CVE-2016-7123 | Candidate | Cross-site request forgery (CSRF) vulnerability in the admin web interface in GNU Mailman before 2.1.15 allows remote attackers to hijack the authentication of administrators. | Assigned (20160902) | None (candidate not yet proposed) | View | |
93944 | CVE-2016-7124 | Candidate | ext/standard/var_unserializer.c in PHP before 5.6.25 and 7.x before 7.0.10 mishandles certain invalid objects, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted serialized data that leads to a (1) __destruct call or (2) magic method call. | Assigned (20160902) | None (candidate not yet proposed) | View | |
93945 | CVE-2016-7125 | Candidate | ext/session/session.c in PHP before 5.6.25 and 7.x before 7.0.10 skips invalid session names in a way that triggers incorrect parsing, which allows remote attackers to inject arbitrary-type session data by leveraging control of a session name, as demonstrated by object injection. | Assigned (20160902) | None (candidate not yet proposed) | View |
Page 18789 of 20943, showing 5 records out of 104715 total, starting on record 93941, ending on 93945