CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
94221 | CVE-2016-7401 | Candidate | The cookie parsing code in Django before 1.8.15 and 1.9.x before 1.9.10, when used on a site with Google Analytics, allows remote attackers to bypass an intended CSRF protection mechanism by setting arbitrary cookies. | Assigned (20160909) | None (candidate not yet proposed) | View | |
94222 | CVE-2016-7402 | Candidate | SAP ASE 16.0 SP02 PL03 and prior versions allow attackers who own SourceDB and TargetDB databases to elevate privileges to sa (system administrator) via dbcc import_sproc SQL injection. | Assigned (20160909) | None (candidate not yet proposed) | View | |
94223 | CVE-2016-7403 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20160909) | None (candidate not yet proposed) | View | |
94224 | CVE-2016-7404 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20160909) | None (candidate not yet proposed) | View | |
94225 | CVE-2016-7405 | Candidate | The qstr method in the PDO driver in the ADOdb Library for PHP before 5.x before 5.20.7 might allow remote attackers to conduct SQL injection attacks via vectors related to incorrect quoting. | Assigned (20160909) | None (candidate not yet proposed) | View |
Page 18845 of 20943, showing 5 records out of 104715 total, starting on record 94221, ending on 94225