NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
20452 | CVE-2016-5099 | Cross-site scripting (XSS) vulnerability in phpMyAdmin 4.4.x before 4.4.15.6 and 4.6.x before 4.6.2 allows remote attackers to inject arbitrary web script or HTML via special characters that are mishandled during double URL decoding. | 2 | 4.3 | Medium | 2017-01-19 | 2016-11-28 | View | |
20451 | CVE-2016-5098 | Directory traversal vulnerability in libraries/error_report.lib.php in phpMyAdmin before 4.6.2-prerelease allows remote attackers to determine the existence of arbitrary files by triggering an error. | 2 | 5 | Medium | 2017-01-19 | 2016-07-14 | View | |
20450 | CVE-2016-5097 | phpMyAdmin before 4.6.2 places tokens in query strings and does not arrange for them to be stripped before external navigation, which allows remote attackers to obtain sensitive information by reading (1) HTTP requests or (2) server logs. | 2 | 5 | Medium | 2017-01-19 | 2016-07-14 | View | |
20449 | CVE-2016-5096 | Integer overflow in the fread function in ext/standard/file.c in PHP before 5.5.36 and 5.6.x before 5.6.22 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a large integer in the second argument. | 2 | 7.5 | High | 2017-01-19 | 2016-11-28 | View | |
20448 | CVE-2016-5095 | Integer overflow in the php_escape_html_entities_ex function in ext/standard/html.c in PHP before 5.5.36 and 5.6.x before 5.6.22 allows remote attackers to cause a denial of service or possibly have unspecified other impact by triggering a large output string from a FILTER_SANITIZE_FULL_SPECIAL_CHARS filter_var call. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-5094. | 2 | 7.5 | High | 2017-01-19 | 2016-11-28 | View |
Page 1618 of 17672, showing 5 records out of 88360 total, starting on record 8086, ending on 8090