NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
21028 | CVE-2016-6128 | The gdImageCropThreshold function in gd_crop.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 7.0.9, allows remote attackers to cause a denial of service (application crash) via an invalid color index. | 2 | 5 | Medium | 2017-01-19 | 2016-11-28 | View | |
81852 | CVE-2016-6126 | IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. | 2 | 4 | Medium | 2017-02-08 | 2017-02-07 | View | |
81851 | CVE-2016-6125 | IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | 2 | 3.5 | Low | 2017-02-08 | 2017-02-05 | View | |
81850 | CVE-2016-6124 | IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server. | 2 | 6.5 | Medium | 2017-02-08 | 2017-02-07 | View | |
81849 | CVE-2016-6123 | IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | 2 | 3.5 | Low | 2017-02-08 | 2017-02-05 | View |
Page 1465 of 17672, showing 5 records out of 88360 total, starting on record 7321, ending on 7325