CVE List

Id CVE No. Status Description Phase Votes Comments Actions
96271  CVE-2016-9451  Candidate  Confirmation forms in Drupal 7.x before 7.52 make it easier for remote authenticated users to conduct open redirect attacks via unspecified vectors.  Assigned (20161118)  None (candidate not yet proposed)    View
96272  CVE-2016-9452  Candidate  The transliterate mechanism in Drupal 8.x before 8.2.3 allows remote attackers to cause a denial of service via a crafted URL.  Assigned (20161118)  None (candidate not yet proposed)    View
96273  CVE-2016-9453  Candidate  The t2p_readwrite_pdf_image_tile function in LibTIFF allows remote attackers to cause a denial of service (out-of-bounds write and crash) or possibly execute arbitrary code via a JPEG file with a TIFFTAG_JPEGTABLES of length one.  Assigned (20161118)  None (candidate not yet proposed)    View
96274  CVE-2016-9454  Candidate  Revive Adserver before 3.2.3 suffers from Persistent XSS. A vector for persistent XSS attacks via the Revive Adserver user interface exists, requiring a trusted (non-admin) account. The banner image URL for external banners wasn"t properly escaped when displayed in most of the banner related pages.  Assigned (20161119)  None (candidate not yet proposed)    View
96275  CVE-2016-9455  Candidate  Revive Adserver before 3.2.3 suffers from Cross-Site Request Forgery (CSRF). A number of scripts in Revive Adserver"s user interface are vulnerable to CSRF attacks: `www/admin/banner-acl.php`, `www/admin/banner-activate.php`, `www/admin/banner-advanced.php`, `www/admin/banner-modify.php`, `www/admin/banner-swf.php`, `www/admin/banner-zone.php`, `www/admin/tracker-modify.php`.  Assigned (20161119)  None (candidate not yet proposed)    View

Page 19255 of 20943, showing 5 records out of 104715 total, starting on record 96271, ending on 96275

Actions