NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
21680 | CVE-2016-7153 | The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack. | 2 | 5 | Medium | 2017-01-19 | 2016-11-28 | View | |
21679 | CVE-2016-7152 | The HTTPS protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack. | 2 | 5 | Medium | 2017-01-19 | 2016-11-28 | View | |
21678 | CVE-2016-7150 | Cross-site scripting (XSS) vulnerability in b2evolution 6.7.5 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the site name. | 2 | 3.5 | Low | 2017-01-30 | 2017-01-23 | View | |
21677 | CVE-2016-7149 | Cross-site scripting (XSS) vulnerability in b2evolution 6.7.5 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors related to the autolink function. | 2 | 4.3 | Medium | 2017-01-30 | 2017-01-23 | View | |
21676 | CVE-2016-7148 | MoinMoin 1.9.8 allows remote attackers to conduct "JavaScript injection" attacks by using the "page creation" approach, related to a "Cross Site Scripting (XSS)" issue affecting the action=AttachFile (via page name) component. | 2 | 4.3 | Medium | 2017-02-06 | 2017-01-31 | View |
Page 1313 of 17672, showing 5 records out of 88360 total, starting on record 6561, ending on 6565