CVE List

Id CVE No. Status Description Phase Votes Comments Actions
94721  CVE-2016-7901  Candidate  ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.  Assigned (20160909)  None (candidate not yet proposed)    View
94722  CVE-2016-7902  Candidate  Unrestricted file upload vulnerability in the fileUnzip->unzip method in Dotclear before 2.10.3 allows remote authenticated users with permissions to manage media items to execute arbitrary code by uploading a ZIP file containing a file with a crafted extension, as demonstrated by .php.txt or .php%20.  Assigned (20160909)  None (candidate not yet proposed)    View
94723  CVE-2016-7903  Candidate  Dotclear before 2.10.3, when the Host header is not part of the web server routing process, allows remote attackers to modify the password reset address link via the HTTP Host header.  Assigned (20160909)  None (candidate not yet proposed)    View
94724  CVE-2016-7904  Candidate  Cross-site request forgery (CSRF) vulnerability in CMS Made Simple before 2.1.6 allows remote attackers to hijack the authentication of administrators for requests that create accounts via an admin/adduser.php request.  Assigned (20160909)  None (candidate not yet proposed)    View
94725  CVE-2016-7905  Candidate  The read_gab2_sub function in libavformat/avidec.c in FFmpeg before 3.1.4 allows remote attackers to cause a denial of service (NULL pointer used) via a crafted AVI file.  Assigned (20160909)  None (candidate not yet proposed)    View

Page 18945 of 20943, showing 5 records out of 104715 total, starting on record 94721, ending on 94725

Actions