CVE List

Id CVE No. Status Description Phase Votes Comments Actions
94221  CVE-2016-7401  Candidate  The cookie parsing code in Django before 1.8.15 and 1.9.x before 1.9.10, when used on a site with Google Analytics, allows remote attackers to bypass an intended CSRF protection mechanism by setting arbitrary cookies.  Assigned (20160909)  None (candidate not yet proposed)    View
94222  CVE-2016-7402  Candidate  SAP ASE 16.0 SP02 PL03 and prior versions allow attackers who own SourceDB and TargetDB databases to elevate privileges to sa (system administrator) via dbcc import_sproc SQL injection.  Assigned (20160909)  None (candidate not yet proposed)    View
94223  CVE-2016-7403  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20160909)  None (candidate not yet proposed)    View
94224  CVE-2016-7404  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20160909)  None (candidate not yet proposed)    View
94225  CVE-2016-7405  Candidate  The qstr method in the PDO driver in the ADOdb Library for PHP before 5.x before 5.20.7 might allow remote attackers to conduct SQL injection attacks via vectors related to incorrect quoting.  Assigned (20160909)  None (candidate not yet proposed)    View

Page 18845 of 20943, showing 5 records out of 104715 total, starting on record 94221, ending on 94225

Actions