CVE List

Id CVE No. Status Description Phase Votes Comments Actions
96136  CVE-2016-9316  Candidate  Multiple stored Cross-Site-Scripting (XSS) vulnerabilities in com.trend.iwss.gui.servlet.updateaccountadministration in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) version 6.5-SP2_Build_Linux_1707 and earlier allow authenticated, remote users with least privileges to inject arbitrary HTML/JavaScript code into web pages. This was resolved in Version 6.5 CP 1737.  Assigned (20161114)  None (candidate not yet proposed)    View
96137  CVE-2016-9317  Candidate  The gdImageCreate function in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to cause a denial of service (system hang) via an oversized image.  Assigned (20161114)  None (candidate not yet proposed)    View
96138  CVE-2016-9318  Candidate  libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other products, does not offer a flag directly indicating that the current document may be read but other files may not be opened, which makes it easier for remote attackers to conduct XML External Entity (XXE) attacks via a crafted document.  Assigned (20161114)  None (candidate not yet proposed)    View
96139  CVE-2016-9319  Candidate  There is Missing SSL Certificate Validation in the Trend Micro Enterprise Mobile Security Android Application before 9.7.1193, aka VRTS-398.  Assigned (20161114)  None (candidate not yet proposed)    View
96140  CVE-2016-9320  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20161114)  None (candidate not yet proposed)    View

Page 19228 of 20943, showing 5 records out of 104715 total, starting on record 96136, ending on 96140

Actions