NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
21657 | CVE-2016-7119 | Cross-site scripting (XSS) vulnerability in the user-profile biography section in DotNetNuke (DNN) before 8.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted onclick attribute in an IMG element. | 2 | 3.5 | Low | 2017-01-19 | 2016-11-28 | View | |
21658 | CVE-2016-7122 | The avi_read_nikon function in libavformat/avidec.c in FFmpeg before 3.1.4 is vulnerable to infinite loop when it decodes an AVI file that has a crafted "nctg" structure. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-23 | View | |
21659 | CVE-2016-7123 | Cross-site request forgery (CSRF) vulnerability in the admin web interface in GNU Mailman before 2.1.15 allows remote attackers to hijack the authentication of administrators. | 2 | 6.8 | Medium | 2017-01-19 | 2016-11-28 | View | |
21660 | CVE-2016-7124 | ext/standard/var_unserializer.c in PHP before 5.6.25 and 7.x before 7.0.10 mishandles certain invalid objects, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted serialized data that leads to a (1) __destruct call or (2) magic method call. | 2 | 7.5 | High | 2017-01-19 | 2016-11-28 | View | |
21661 | CVE-2016-7125 | ext/session/session.c in PHP before 5.6.25 and 7.x before 7.0.10 skips invalid session names in a way that triggers incorrect parsing, which allows remote attackers to inject arbitrary-type session data by leveraging control of a session name, as demonstrated by object injection. | 2 | 5 | Medium | 2017-01-19 | 2016-11-28 | View |
Page 16356 of 17672, showing 5 records out of 88360 total, starting on record 81776, ending on 81780