NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
20608 | CVE-2016-5300 | The XML parser in Expat does not use sufficient entropy for hash initialization, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted identifiers in an XML document. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0876. | 2 | 7.8 | High | 2017-01-19 | 2016-11-29 | View | |
20609 | CVE-2016-5301 | The parse_chunk_header function in libtorrent before 1.1.1 allows remote attackers to cause a denial of service (crash) via a crafted (1) HTTP response or possibly a (2) UPnP broadcast. | 2 | 5 | Medium | 2017-01-19 | 2016-11-29 | View | |
20610 | CVE-2016-5302 | Citrix XenServer 7.0 before Hotfix XS70E003, when a deployment has been upgraded from an earlier release, might allow remote attackers on the management network to "compromise" a host by leveraging credentials for an Active Directory account. | 2 | 7.5 | High | 2017-01-19 | 2016-06-20 | View | |
20611 | CVE-2016-5303 | Cross-site scripting (XSS) vulnerability in the Horde Text Filter API in Horde Groupware and Horde Groupware Webmail Edition before 5.2.16 allows remote attackers to inject arbitrary web script or HTML via crafted data:text/html content in a form (1) action or (2) xlink attribute. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-22 | View | |
20612 | CVE-2016-5304 | Open redirect vulnerability in a report-routing component in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. | 2 | 4.9 | Medium | 2017-01-19 | 2016-07-01 | View |
Page 16089 of 17672, showing 5 records out of 88360 total, starting on record 80441, ending on 80445