NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
84023 | CVE-2016-9456 | Revive Adserver before 3.2.3 suffers from Cross-Site Request Forgery (CSRF). The Revive Adserver team conducted a security audit of the admin interface scripts in order to identify and fix other potential CSRF vulnerabilities. Over 20+ such issues were fixed. | 2 | 6.8 | Medium | 2017-03-29 | 2017-03-29 | View | |
84022 | CVE-2016-9455 | Revive Adserver before 3.2.3 suffers from Cross-Site Request Forgery (CSRF). A number of scripts in Revive Adserver"s user interface are vulnerable to CSRF attacks: `www/admin/banner-acl.php`, `www/admin/banner-activate.php`, `www/admin/banner-advanced.php`, `www/admin/banner-modify.php`, `www/admin/banner-swf.php`, `www/admin/banner-zone.php`, `www/admin/tracker-modify.php`. | 2 | 6.8 | Medium | 2017-03-29 | 2017-03-29 | View | |
84021 | CVE-2016-9454 | Revive Adserver before 3.2.3 suffers from Persistent XSS. A vector for persistent XSS attacks via the Revive Adserver user interface exists, requiring a trusted (non-admin) account. The banner image URL for external banners wasn"t properly escaped when displayed in most of the banner related pages. | 2 | 3.5 | Low | 2017-03-29 | 2017-03-29 | View | |
82119 | CVE-2016-9453 | The t2p_readwrite_pdf_image_tile function in LibTIFF allows remote attackers to cause a denial of service (out-of-bounds write and crash) or possibly execute arbitrary code via a JPEG file with a TIFFTAG_JPEGTABLES of length one. | 2 | 6.8 | Medium | 2017-02-08 | 2017-02-07 | View | |
22394 | CVE-2016-9452 | The transliterate mechanism in Drupal 8.x before 8.2.3 allows remote attackers to cause a denial of service via a crafted URL. | 2 | 4.3 | Medium | 2017-01-19 | 2016-11-29 | View |
Page 1042 of 17672, showing 5 records out of 88360 total, starting on record 5206, ending on 5210