CVE List

Id CVE No. Status Description Phase Votes Comments Actions
94391  CVE-2016-7571  Candidate  Cross-site scripting (XSS) vulnerability in Drupal 8.x before 8.1.10 allows remote attackers to inject arbitrary web script or HTML via vectors involving an HTTP exception.  Assigned (20160909)  None (candidate not yet proposed)    View
94392  CVE-2016-7572  Candidate  The system.temporary route in Drupal 8.x before 8.1.10 does not properly check for "Export configuration" permission, which allows remote authenticated users to bypass intended access restrictions and read a full config export via unspecified vectors.  Assigned (20160909)  None (candidate not yet proposed)    View
94393  CVE-2016-7573  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20160909)  None (candidate not yet proposed)    View
94394  CVE-2016-7574  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20160909)  None (candidate not yet proposed)    View
94395  CVE-2016-7575  Candidate  ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-7575. Reason: This candidate is a duplicate of CVE-2015-7575. A typo caused the wrong ID to be used. Notes: All CVE users should reference CVE-2015-7575 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.  Assigned (20160225)  None (candidate not yet proposed)    View

Page 18879 of 20943, showing 5 records out of 104715 total, starting on record 94391, ending on 94395

Actions