NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
20906  CVE-2016-5691  The DCM reader in ImageMagick before 6.9.4-5 and 7.x before 7.0.1-7 allows remote attackers to have unspecified impact by leveraging lack of validation of (1) pixel.red, (2) pixel.green, and (3) pixel.blue.    7.5  High  2017-01-19  2016-12-16  View
20669  CVE-2016-5407  The (1) XvQueryAdaptors and (2) XvQueryEncodings functions in X.org libXv before 1.0.11 allow remote X servers to trigger out-of-bounds memory access operations via vectors involving length specifications in received data.    7.5  High  2017-01-19  2016-12-16  View
20931  CVE-2016-5740  An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev5. JavaScript code can be used as part of ical attachments within scheduling E-Mails. This content, for example an appointment"s location, will be presented to the user at the E-Mail App, depending on the invitation workflow. This code gets executed within the context of the user"s current session. Malicious script code can be executed within a user"s context. This can lead to session hijacking or triggering unwanted actions via the web interface (sending mail, deleting data etc.).    4.3  Medium  2017-01-19  2016-12-16  View
21478  CVE-2016-6842  An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. Setting the user"s name to JS code makes that code execute when selecting that user"s "Templates" folder from OX Documents settings. This requires the folder to be shared to the victim. Malicious script code can be executed within a user"s context. This can lead to session hijacking or triggering unwanted actions via the web interface (sending mail, deleting data etc.).    4.3  Medium  2017-01-19  2016-12-16  View
21479  CVE-2016-6843  An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. Script code can be injected to contact names. When adding those contacts to a group, the script code gets executed in the context of the user which creates or changes the group by using autocomplete. In most cases this is a user with elevated permissions. Malicious script code can be executed within a user"s context. This can lead to session hijacking or triggering unwanted actions via the web interface (sending mail, deleting data etc.).    4.3  Medium  2017-01-19  2016-12-16  View

Page 14377 of 17672, showing 5 records out of 88360 total, starting on record 71881, ending on 71885

Actions