NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
22313 | CVE-2016-9190 | Pillow before 3.3.2 allows context-dependent attackers to execute arbitrary code by using the "crafted image file" approach, related to an "Insecure Sign Extension" issue affecting the ImagingNew in Storage.c component. | 2 | 6.8 | Medium | 2017-01-19 | 2017-01-10 | View | |
22312 | CVE-2016-9189 | Pillow before 3.3.2 allows context-dependent attackers to obtain sensitive information by using the "crafted image file" approach, related to an "Integer Overflow" issue affecting the Image.core.map_buffer in map.c component. | 2 | 4.3 | Medium | 2017-01-19 | 2017-01-10 | View | |
22311 | CVE-2016-9188 | Cross-site scripting (XSS) vulnerabilities in Moodle CMS on or before 3.1.2 allow remote attackers to inject arbitrary web script or HTML via the s_additionalhtmlhead, s_additionalhtmltopofbody, and s_additionalhtmlfooter parameters. | 2 | 4.3 | Medium | 2017-01-19 | 2016-11-29 | View | |
22310 | CVE-2016-9187 | Unrestricted file upload vulnerability in the double extension support in the "image" module in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors. | 2 | 6.5 | Medium | 2017-01-19 | 2016-11-29 | View | |
22309 | CVE-2016-9186 | Unrestricted file upload vulnerability in the "legacy course files" and "file manager" modules in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors. | 2 | 6.5 | Medium | 2017-01-19 | 2016-11-29 | View |
Page 1078 of 17672, showing 5 records out of 88360 total, starting on record 5386, ending on 5390