NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
22313  CVE-2016-9190  Pillow before 3.3.2 allows context-dependent attackers to execute arbitrary code by using the "crafted image file" approach, related to an "Insecure Sign Extension" issue affecting the ImagingNew in Storage.c component.    6.8  Medium  2017-01-19  2017-01-10  View
22312  CVE-2016-9189  Pillow before 3.3.2 allows context-dependent attackers to obtain sensitive information by using the "crafted image file" approach, related to an "Integer Overflow" issue affecting the Image.core.map_buffer in map.c component.    4.3  Medium  2017-01-19  2017-01-10  View
22311  CVE-2016-9188  Cross-site scripting (XSS) vulnerabilities in Moodle CMS on or before 3.1.2 allow remote attackers to inject arbitrary web script or HTML via the s_additionalhtmlhead, s_additionalhtmltopofbody, and s_additionalhtmlfooter parameters.    4.3  Medium  2017-01-19  2016-11-29  View
22310  CVE-2016-9187  Unrestricted file upload vulnerability in the double extension support in the "image" module in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors.    6.5  Medium  2017-01-19  2016-11-29  View
22309  CVE-2016-9186  Unrestricted file upload vulnerability in the "legacy course files" and "file manager" modules in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors.    6.5  Medium  2017-01-19  2016-11-29  View

Page 1078 of 17672, showing 5 records out of 88360 total, starting on record 5386, ending on 5390

Actions