NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
21981 | CVE-2016-7966 | Through a malicious URL that contained a quote character it was possible to inject HTML code in KMail"s plaintext viewer. Due to the parser used on the URL it was not possible to include the equal sign (=) or a space into the injected HTML, which greatly reduces the available HTML functionality. Although it is possible to include an HTML comment indicator to hide content. | 2 | 7.5 | High | 2017-01-19 | 2016-12-27 | View | |
21980 | CVE-2016-7965 | DokuWiki 2016-06-26a and older uses $_SERVER[HTTP_HOST] instead of the baseurl setting as part of the password-reset URL. This can lead to phishing attacks. (A remote unauthenticated attacker can change the URL"s hostname via the HTTP Host header.) The vulnerability can be triggered only if the Host header is not part of the web server routing process (e.g., if several domains are served by the same web server). | 2 | 4.3 | Medium | 2017-01-19 | 2016-11-28 | View | |
21979 | CVE-2016-7964 | The sendRequest method in HTTPClient Class in file /inc/HTTPClient.php in DokuWiki 2016-06-26a and older, when media file fetching is enabled, has no way to restrict access to private networks. This allows users to scan ports of internal networks via SSRF, such as 10.0.0.1/8, 172.16.0.0/12, and 192.168.0.0/16. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-02 | View | |
21978 | CVE-2016-7960 | Siemens SIMATIC STEP 7 (TIA Portal) before 14 uses an improper format for managing TIA project files during version updates, which makes it easier for local users to obtain sensitive configuration information via unspecified vectors. | 2 | 1.9 | Low | 2017-01-19 | 2016-12-22 | View | |
21977 | CVE-2016-7959 | Siemens SIMATIC STEP 7 (TIA Portal) before 14 improperly stores pre-shared key data in TIA project files, which makes it easier for local users to obtain sensitive information by leveraging access to a file and conducting a brute-force attack. | 2 | 1.9 | Low | 2017-01-19 | 2016-12-21 | View |
Page 1212 of 17672, showing 5 records out of 88360 total, starting on record 6056, ending on 6060