NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
21092 | CVE-2016-6283 | Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.10.6 allows remote attackers to inject arbitrary web script or HTML via the newFileName parameter to pages/doeditattachment.action. | 2017-01-19 | 2017-01-18 | View | ||||
81863 | CVE-2016-6285 | Cross-site scripting (XSS) vulnerability in includes/decorators/global-translations.jsp in Atlassian JIRA before 7.2.2 allows remote attackers to inject arbitrary web script or HTML via the HTTP Host header. | 2 | 4.3 | Medium | 2017-02-08 | 2017-02-03 | View | |
21093 | CVE-2016-6286 | The "spiffy-cgi-handlers" egg would convert a nonexistent "Proxy" header to the HTTP_PROXY environment variable, which would allow attackers to direct CGI programs which use this environment variable to use an attacker-specified HTTP proxy server (also known as a "httpoxy" attack). This affects all versions of spiffy-cgi-handlers before 0.5. | 2 | 5 | Medium | 2017-01-19 | 2017-01-10 | View | |
21094 | CVE-2016-6287 | The "http-client" egg always used a HTTP_PROXY environment variable to determine whether HTTP traffic should be routed via a proxy, even when running as a CGI process. Under several web servers this would mean a user-supplied "Proxy" header could allow an attacker to direct all HTTP requests through a proxy (also known as a "httpoxy" attack). This affects all versions of http-client before 0.10. | 2 | 5 | Medium | 2017-01-19 | 2017-01-10 | View | |
21095 | CVE-2016-6288 | The php_url_parse_ex function in ext/standard/url.c in PHP before 5.5.38 allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via vectors involving the smart_str data type. | 2 | 7.5 | High | 2017-01-19 | 2016-09-26 | View |
Page 16228 of 17672, showing 5 records out of 88360 total, starting on record 81136, ending on 81140