CVE List

Id CVE No. Status Description Phase Votes Comments Actions
96006  CVE-2016-9186  Candidate  Unrestricted file upload vulnerability in the "legacy course files" and "file manager" modules in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors.  Assigned (20161104)  None (candidate not yet proposed)    View
96007  CVE-2016-9187  Candidate  Unrestricted file upload vulnerability in the double extension support in the "image" module in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors.  Assigned (20161104)  None (candidate not yet proposed)    View
96008  CVE-2016-9188  Candidate  Cross-site scripting (XSS) vulnerabilities in Moodle CMS on or before 3.1.2 allow remote attackers to inject arbitrary web script or HTML via the s_additionalhtmlhead, s_additionalhtmltopofbody, and s_additionalhtmlfooter parameters.  Assigned (20161104)  None (candidate not yet proposed)    View
96009  CVE-2016-9189  Candidate  Pillow before 3.3.2 allows context-dependent attackers to obtain sensitive information by using the "crafted image file" approach, related to an "Integer Overflow" issue affecting the Image.core.map_buffer in map.c component.  Assigned (20161104)  None (candidate not yet proposed)    View
96010  CVE-2016-9190  Candidate  Pillow before 3.3.2 allows context-dependent attackers to execute arbitrary code by using the "crafted image file" approach, related to an "Insecure Sign Extension" issue affecting the ImagingNew in Storage.c component.  Assigned (20161104)  None (candidate not yet proposed)    View

Page 19202 of 20943, showing 5 records out of 104715 total, starting on record 96006, ending on 96010

Actions