CVE List

Id CVE No. Status Description Phase Votes Comments Actions
94236  CVE-2016-7416  Candidate  ext/intl/msgformat/msgformat_format.c in PHP before 5.6.26 and 7.x before 7.0.11 does not properly restrict the locale length provided to the Locale class in the ICU library, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a MessageFormatter::formatMessage call with a long first argument.  Assigned (20160909)  None (candidate not yet proposed)    View
94237  CVE-2016-7417  Candidate  ext/spl/spl_array.c in PHP before 5.6.26 and 7.x before 7.0.11 proceeds with SplArray unserialization without validating a return value and data type, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted serialized data.  Assigned (20160909)  None (candidate not yet proposed)    View
94238  CVE-2016-7418  Candidate  The php_wddx_push_element function in ext/wddx/wddx.c in PHP before 5.6.26 and 7.x before 7.0.11 allows remote attackers to cause a denial of service (invalid pointer access and out-of-bounds read) or possibly have unspecified other impact via an incorrect boolean element in a wddxPacket XML document, leading to mishandling in a wddx_deserialize call.  Assigned (20160909)  None (candidate not yet proposed)    View
94239  CVE-2016-7419  Candidate  Cross-site scripting (XSS) vulnerability in share.js in the gallery application in ownCloud Server before 9.0.4 and Nextcloud Server before 9.0.52 allows remote authenticated users to inject arbitrary web script or HTML via a crafted directory name.  Assigned (20160909)  None (candidate not yet proposed)    View
94240  CVE-2016-7420  Candidate  Crypto++ (aka cryptopp) through 5.6.4 does not document the requirement for a compile-time NDEBUG definition disabling the many assert calls that are unintended in production use, which might allow context-dependent attackers to obtain sensitive information by leveraging access to process memory after an assertion failure, as demonstrated by reading a core dump.  Assigned (20160909)  None (candidate not yet proposed)    View

Page 18848 of 20943, showing 5 records out of 104715 total, starting on record 94236, ending on 94240

Actions