NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
21985  CVE-2016-7981  Cross-site scripting (XSS) vulnerability in valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the var_url parameter in a valider_xml action.    4.3  Medium  2017-01-30  2017-01-23  View
21984  CVE-2016-7980  Cross-site request forgery (CSRF) vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to hijack the authentication of administrators for requests that execute the XML validator on a local file via a crafted valider_xml request. NOTE: this issue can be combined with CVE-2016-7998 to execute arbitrary PHP code.    6.8  Medium  2017-05-27  2017-05-23  View
86377  CVE-2016-7979  Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently execute arbitrary code by leveraging type confusion in .initialize_dsc_parser.    7.5  High  2017-06-04  2017-05-30  View
86376  CVE-2016-7978  Use-after-free vulnerability in Ghostscript 9.20 might allow remote attackers to execute arbitrary code via vectors related to a reference leak in .setdevice.    7.5  High  2017-06-04  2017-05-30  View
86375  CVE-2016-7977  Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently read arbitrary files via the use of the .libfile operator in a crafted postscript document.    4.3  Medium  2017-06-04  2017-06-01  View

Page 1210 of 17672, showing 5 records out of 88360 total, starting on record 6046, ending on 6050

Actions