CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
96006 | CVE-2016-9186 | Candidate | Unrestricted file upload vulnerability in the "legacy course files" and "file manager" modules in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors. | Assigned (20161104) | None (candidate not yet proposed) | View | |
96007 | CVE-2016-9187 | Candidate | Unrestricted file upload vulnerability in the double extension support in the "image" module in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors. | Assigned (20161104) | None (candidate not yet proposed) | View | |
96008 | CVE-2016-9188 | Candidate | Cross-site scripting (XSS) vulnerabilities in Moodle CMS on or before 3.1.2 allow remote attackers to inject arbitrary web script or HTML via the s_additionalhtmlhead, s_additionalhtmltopofbody, and s_additionalhtmlfooter parameters. | Assigned (20161104) | None (candidate not yet proposed) | View | |
96009 | CVE-2016-9189 | Candidate | Pillow before 3.3.2 allows context-dependent attackers to obtain sensitive information by using the "crafted image file" approach, related to an "Integer Overflow" issue affecting the Image.core.map_buffer in map.c component. | Assigned (20161104) | None (candidate not yet proposed) | View | |
96010 | CVE-2016-9190 | Candidate | Pillow before 3.3.2 allows context-dependent attackers to execute arbitrary code by using the "crafted image file" approach, related to an "Insecure Sign Extension" issue affecting the ImagingNew in Storage.c component. | Assigned (20161104) | None (candidate not yet proposed) | View |
Page 19202 of 20943, showing 5 records out of 104715 total, starting on record 96006, ending on 96010