NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
21985 | CVE-2016-7981 | Cross-site scripting (XSS) vulnerability in valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the var_url parameter in a valider_xml action. | 2 | 4.3 | Medium | 2017-01-30 | 2017-01-23 | View | |
21984 | CVE-2016-7980 | Cross-site request forgery (CSRF) vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to hijack the authentication of administrators for requests that execute the XML validator on a local file via a crafted valider_xml request. NOTE: this issue can be combined with CVE-2016-7998 to execute arbitrary PHP code. | 2 | 6.8 | Medium | 2017-05-27 | 2017-05-23 | View | |
86377 | CVE-2016-7979 | Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently execute arbitrary code by leveraging type confusion in .initialize_dsc_parser. | 2 | 7.5 | High | 2017-06-04 | 2017-05-30 | View | |
86376 | CVE-2016-7978 | Use-after-free vulnerability in Ghostscript 9.20 might allow remote attackers to execute arbitrary code via vectors related to a reference leak in .setdevice. | 2 | 7.5 | High | 2017-06-04 | 2017-05-30 | View | |
86375 | CVE-2016-7977 | Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently read arbitrary files via the use of the .libfile operator in a crafted postscript document. | 2 | 4.3 | Medium | 2017-06-04 | 2017-06-01 | View |
Page 1210 of 17672, showing 5 records out of 88360 total, starting on record 6046, ending on 6050