NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
82868  CVE-2016-9909  The serializer in html5lib before 0.99999999 might allow remote attackers to conduct cross-site scripting (XSS) attacks by leveraging mishandling of the < (less than) character in attribute values.    4.3  Medium  2017-02-28  2017-02-23  View
17844  CVE-2016-1435  Cisco 8800 phones with software 11.0(1) do not properly enforce mounted-filesystem permissions, which allows local users to write to arbitrary files by leveraging shell access, aka Bug ID CSCuz03014.    6.2  Medium  2017-01-19  2016-11-29  View
83380  CVE-2017-6486  A Cross-Site Scripting (XSS) issue was discovered in reasoncms before 4.7.1. The vulnerability exists due to insufficient filtration of user-supplied data (nyroModalSel) passed to the reasoncms-master/www/nyroModal/demoSent.php URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.    4.3  Medium  2017-03-18  2017-03-07  View
18356  CVE-2016-2049  examples/consumer/common.php in JanRain PHP OpenID library (aka php-openid) improperly checks the openid.realm parameter against the SERVER_NAME element in the SERVER superglobal array, which might allow remote attackers to hijack the authentication of arbitrary users via vectors involving a crafted HTTP Host header.    6.8  Medium  2017-01-19  2016-03-04  View
18612  CVE-2016-2387  Multiple cross-site scripting (XSS) vulnerabilities in the Java Proxy Runtime ProxyServer servlet in SAP NetWeaver 7.4 allow remote attackers to inject arbitrary web script or HTML via the (1) ns or (2) interface parameter to ProxyServer/register, aka SAP Security Note 2220571.    4.3  Medium  2017-01-19  2016-11-30  View

Page 14994 of 17672, showing 5 records out of 88360 total, starting on record 74966, ending on 74970

Actions