NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
20169 | CVE-2016-4552 | Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.2.0 allows remote attackers to inject arbitrary web script or HTML via the href attribute in an area tag in an e-mail message. | 2 | 4.3 | Medium | 2017-01-19 | 2017-01-17 | View | |
20170 | CVE-2016-4553 | client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10 does not properly ignore the Host header when absolute-URI is provided, which allows remote attackers to conduct cache-poisoning attacks via an HTTP request. | 2 | 5 | Medium | 2017-01-19 | 2016-11-29 | View | |
20171 | CVE-2016-4554 | mime_header.cc in Squid before 3.5.18 allows remote attackers to bypass intended same-origin restrictions and possibly conduct cache-poisoning attacks via a crafted HTTP Host header, aka a "header smuggling" issue. | 2 | 5 | Medium | 2017-01-19 | 2016-11-29 | View | |
20172 | CVE-2016-4555 | client_side_request.cc in Squid 3.x before 3.5.18 and 4.x before 4.0.10 allows remote servers to cause a denial of service (crash) via crafted Edge Side Includes (ESI) responses. | 2 | 5 | Medium | 2017-01-19 | 2016-11-29 | View | |
20173 | CVE-2016-4556 | Double free vulnerability in Esi.cc in Squid 3.x before 3.5.18 and 4.x before 4.0.10 allows remote servers to cause a denial of service (crash) via a crafted Edge Side Includes (ESI) response. | 2 | 5 | Medium | 2017-01-19 | 2016-11-29 | View |
Page 15970 of 17672, showing 5 records out of 88360 total, starting on record 79846, ending on 79850