CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
96271 | CVE-2016-9451 | Candidate | Confirmation forms in Drupal 7.x before 7.52 make it easier for remote authenticated users to conduct open redirect attacks via unspecified vectors. | Assigned (20161118) | None (candidate not yet proposed) | View | |
96272 | CVE-2016-9452 | Candidate | The transliterate mechanism in Drupal 8.x before 8.2.3 allows remote attackers to cause a denial of service via a crafted URL. | Assigned (20161118) | None (candidate not yet proposed) | View | |
96273 | CVE-2016-9453 | Candidate | The t2p_readwrite_pdf_image_tile function in LibTIFF allows remote attackers to cause a denial of service (out-of-bounds write and crash) or possibly execute arbitrary code via a JPEG file with a TIFFTAG_JPEGTABLES of length one. | Assigned (20161118) | None (candidate not yet proposed) | View | |
96274 | CVE-2016-9454 | Candidate | Revive Adserver before 3.2.3 suffers from Persistent XSS. A vector for persistent XSS attacks via the Revive Adserver user interface exists, requiring a trusted (non-admin) account. The banner image URL for external banners wasn"t properly escaped when displayed in most of the banner related pages. | Assigned (20161119) | None (candidate not yet proposed) | View | |
96275 | CVE-2016-9455 | Candidate | Revive Adserver before 3.2.3 suffers from Cross-Site Request Forgery (CSRF). A number of scripts in Revive Adserver"s user interface are vulnerable to CSRF attacks: `www/admin/banner-acl.php`, `www/admin/banner-activate.php`, `www/admin/banner-advanced.php`, `www/admin/banner-modify.php`, `www/admin/banner-swf.php`, `www/admin/banner-zone.php`, `www/admin/tracker-modify.php`. | Assigned (20161119) | None (candidate not yet proposed) | View |
Page 19255 of 20943, showing 5 records out of 104715 total, starting on record 96271, ending on 96275