NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
21485 | CVE-2016-6851 | An issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code can be provided as parameter to the OX Guard guest reader web application. This allows cross-site scripting attacks against arbitrary users since no prior authentication is needed. Malicious script code can be executed within a user"s context. This can lead to session hijacking or triggering unwanted actions via the web interface (sending mail, deleting data etc.) in case the user has an active session on the same domain already. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-16 | View | |
21488 | CVE-2016-6854 | An issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code which got injected to a mail with inline PGP signature gets executed when verifying the signature. Malicious script code can be executed within a user"s context. This can lead to session hijacking or triggering unwanted actions via the web interface (sending mail, deleting data etc.). | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-16 | View | |
18824 | CVE-2016-2840 | An issue was discovered in Open-Xchange Server 6 / OX AppSuite before 7.8.0-rev26. The "session" parameter for file-download requests can be used to inject script code that gets reflected through the subsequent status page. Malicious script code can be executed within a trusted domain"s context. While no OX App Suite specific data can be manipulated, the vulnerability can be exploited without being authenticated and therefore used for social engineering attacks, stealing cookies or redirecting from trustworthy to malicious hosts. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-16 | View | |
83488 | CVE-2017-6907 | An issue was discovered in Open.GL before 2017-03-13. The vulnerability exists due to insufficient filtration of user-supplied data (content) passed to the Open.GL-master/index.php URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website. | 2 | 4.3 | Medium | 2017-04-27 | 2017-03-30 | View | |
82216 | CVE-2017-5153 | An issue was discovered in OSIsoft PI Coresight 2016 R2 and earlier versions, and PI Web API 2016 R2 when deployed using the PI AF Services 2016 R2 integrated install kit. An information exposure through server log files vulnerability has been identified, which may allow service account passwords to become exposed for the affected services, potentially leading to unauthorized shutdown of the affected PI services as well as potential reuse of domain credentials. | 2 | 2.1 | Low | 2017-03-18 | 2017-03-16 | View |
Page 1173 of 17672, showing 5 records out of 88360 total, starting on record 5861, ending on 5865