NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
21657  CVE-2016-7119  Cross-site scripting (XSS) vulnerability in the user-profile biography section in DotNetNuke (DNN) before 8.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted onclick attribute in an IMG element.    3.5  Low  2017-01-19  2016-11-28  View
21658  CVE-2016-7122  The avi_read_nikon function in libavformat/avidec.c in FFmpeg before 3.1.4 is vulnerable to infinite loop when it decodes an AVI file that has a crafted "nctg" structure.    4.3  Medium  2017-01-19  2016-12-23  View
21659  CVE-2016-7123  Cross-site request forgery (CSRF) vulnerability in the admin web interface in GNU Mailman before 2.1.15 allows remote attackers to hijack the authentication of administrators.    6.8  Medium  2017-01-19  2016-11-28  View
21660  CVE-2016-7124  ext/standard/var_unserializer.c in PHP before 5.6.25 and 7.x before 7.0.10 mishandles certain invalid objects, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted serialized data that leads to a (1) __destruct call or (2) magic method call.    7.5  High  2017-01-19  2016-11-28  View
21661  CVE-2016-7125  ext/session/session.c in PHP before 5.6.25 and 7.x before 7.0.10 skips invalid session names in a way that triggers incorrect parsing, which allows remote attackers to inject arbitrary-type session data by leveraging control of a session name, as demonstrated by object injection.    Medium  2017-01-19  2016-11-28  View

Page 16356 of 17672, showing 5 records out of 88360 total, starting on record 81776, ending on 81780

Actions