CVE List

Id CVE No. Status Description Phase Votes Comments Actions
95831  CVE-2016-9011  Candidate  The wmf_malloc function in api.c in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (application crash) via a crafted wmf file, which triggers a memory allocation failure.  Assigned (20161025)  None (candidate not yet proposed)    View
95832  CVE-2016-9012  Candidate  CloudVision Portal (CVP) before 2016.1.2.1 allows remote authenticated users to gain access to the internal configuration mechanisms via the management plane, related to a request to /web/system/console/bundle.  Assigned (20161025)  None (candidate not yet proposed)    View
95833  CVE-2016-9013  Candidate  Django 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3 use a hardcoded password for a temporary database user created when running tests with an Oracle database, which makes it easier for remote attackers to obtain access to the database server by leveraging failure to manually specify a password in the database settings TEST dictionary.  Assigned (20161025)  None (candidate not yet proposed)    View
95834  CVE-2016-9014  Candidate  Django before 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3, when settings.DEBUG is True, allow remote attackers to conduct DNS rebinding attacks by leveraging failure to validate the HTTP Host header against settings.ALLOWED_HOSTS.  Assigned (20161025)  None (candidate not yet proposed)    View
95835  CVE-2016-9015  Candidate  Versions 1.17 and 1.18 of the Python urllib3 library suffer from a vulnerability that can cause them, in certain configurations, to not correctly validate TLS certificates. This places users of the library with those configurations at risk of man-in-the-middle and information leakage attacks. This vulnerability affects users using versions 1.17 and 1.18 of the urllib3 library, who are using the optional PyOpenSSL support for TLS instead of the regular standard library TLS backend, and who are using OpenSSL 1.1.0 via PyOpenSSL. This is an extremely uncommon configuration, so the security impact of this vulnerability is low.  Assigned (20161025)  None (candidate not yet proposed)    View

Page 19167 of 20943, showing 5 records out of 104715 total, starting on record 95831, ending on 95835

Actions