NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
81855 | CVE-2016-6175 | Eval injection vulnerability in php-gettext 1.0.12 and earlier allows remote attackers to execute arbitrary PHP code via a crafted plural forms header. | 2 | 7.5 | High | 2017-02-28 | 2017-02-28 | View | |
81854 | CVE-2016-6163 | The rsvg_pattern_fix_fallback function in rsvg-paint_server.c in librsvg2 2.40.2 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted svg file. | 2 | 4.3 | Medium | 2017-02-08 | 2017-02-07 | View | |
81853 | CVE-2016-6131 | The demangler in GNU Libiberty allows remote attackers to cause a denial of service (infinite loop, stack overflow, and crash) via a cycle in the references of remembered mangled types. | 2 | 5 | Medium | 2017-02-15 | 2017-02-09 | View | |
81852 | CVE-2016-6126 | IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. | 2 | 4 | Medium | 2017-02-08 | 2017-02-07 | View | |
81851 | CVE-2016-6125 | IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | 2 | 3.5 | Low | 2017-02-08 | 2017-02-05 | View |
Page 1302 of 17672, showing 5 records out of 88360 total, starting on record 6506, ending on 6510