NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
82910 | CVE-2016-6233 | The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.19 might allow remote attackers to conduct SQL injection attacks via vectors related to use of the character pattern [w]* in a regular expression. | 2 | 7.5 | High | 2017-02-28 | 2017-02-22 | View | |
82909 | CVE-2016-6191 | Multiple cross-site scripting (XSS) vulnerabilities in the View Raw Source page in the Web Calendar in SOGo before 3.1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) Description, (2) Location, (3) URL, or (4) Title field. | 2 | 4.3 | Medium | 2017-02-28 | 2017-02-22 | View | |
82908 | CVE-2016-6190 | SOGo before 2.3.12 and 3.x before 3.1.1 does not restrict access to the UID and DTSTAMP attributes, which allows remote authenticated users to obtain sensitive information about appointments with the "View the Date & Time" restriction, as demonstrated by correlating UIDs and DTSTAMPs between all users. | 2 | 4 | Medium | 2017-02-28 | 2017-02-22 | View | |
82907 | CVE-2016-6189 | Incomplete blacklist in SOGo before 2.3.12 and 3.x before 3.1.1 allows remote authenticated users to obtain sensitive information by reading the fields in the (1) ics or (2) XML calendar feeds. | 2 | 4 | Medium | 2017-02-28 | 2017-02-22 | View | |
82906 | CVE-2016-6167 | Multiple untrusted search path vulnerabilities in Putty beta 0.67 allow local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse (1) UxTheme.dll or (2) ntmarta.dll file in the current working directory. | 2 | 4.4 | Medium | 2017-02-28 | 2017-02-28 | View |
Page 1091 of 17672, showing 5 records out of 88360 total, starting on record 5451, ending on 5455