NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
21680  CVE-2016-7153  The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.    Medium  2017-01-19  2016-11-28  View
21679  CVE-2016-7152  The HTTPS protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.    Medium  2017-01-19  2016-11-28  View
21678  CVE-2016-7150  Cross-site scripting (XSS) vulnerability in b2evolution 6.7.5 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the site name.    3.5  Low  2017-01-30  2017-01-23  View
21677  CVE-2016-7149  Cross-site scripting (XSS) vulnerability in b2evolution 6.7.5 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors related to the autolink function.    4.3  Medium  2017-01-30  2017-01-23  View
21676  CVE-2016-7148  MoinMoin 1.9.8 allows remote attackers to conduct "JavaScript injection" attacks by using the "page creation" approach, related to a "Cross Site Scripting (XSS)" issue affecting the action=AttachFile (via page name) component.    4.3  Medium  2017-02-06  2017-01-31  View

Page 1313 of 17672, showing 5 records out of 88360 total, starting on record 6561, ending on 6565

Actions