NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
82908  CVE-2016-6190  SOGo before 2.3.12 and 3.x before 3.1.1 does not restrict access to the UID and DTSTAMP attributes, which allows remote authenticated users to obtain sensitive information about appointments with the "View the Date & Time" restriction, as demonstrated by correlating UIDs and DTSTAMPs between all users.    Medium  2017-02-28  2017-02-22  View
82909  CVE-2016-6191  Multiple cross-site scripting (XSS) vulnerabilities in the View Raw Source page in the Web Calendar in SOGo before 3.1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) Description, (2) Location, (3) URL, or (4) Title field.    4.3  Medium  2017-02-28  2017-02-22  View
82910  CVE-2016-6233  The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.19 might allow remote attackers to conduct SQL injection attacks via vectors related to use of the character pattern [w]* in a regular expression.    7.5  High  2017-02-28  2017-02-22  View
82911  CVE-2016-6252  Integer overflow in shadow 4.2.1 allows local users to gain privileges via crafted input to newuidmap.    4.6  Medium  2017-02-28  2017-02-22  View
82912  CVE-2016-6870  Out-of-bounds write in the (1) mb_detect_encoding, (2) mb_send_mail, and (3) mb_detect_order functions in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors.    7.5  High  2017-02-28  2017-02-22  View

Page 15563 of 17672, showing 5 records out of 88360 total, starting on record 77811, ending on 77815

Actions