NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 21676 | CVE-2016-7148 | MoinMoin 1.9.8 allows remote attackers to conduct "JavaScript injection" attacks by using the "page creation" approach, related to a "Cross Site Scripting (XSS)" issue affecting the action=AttachFile (via page name) component. | 2 | 4.3 | Medium | 2017-02-06 | 2017-01-31 | View | |
| 21677 | CVE-2016-7149 | Cross-site scripting (XSS) vulnerability in b2evolution 6.7.5 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors related to the autolink function. | 2 | 4.3 | Medium | 2017-01-30 | 2017-01-23 | View | |
| 21678 | CVE-2016-7150 | Cross-site scripting (XSS) vulnerability in b2evolution 6.7.5 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the site name. | 2 | 3.5 | Low | 2017-01-30 | 2017-01-23 | View | |
| 21679 | CVE-2016-7152 | The HTTPS protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack. | 2 | 5 | Medium | 2017-01-19 | 2016-11-28 | View | |
| 21680 | CVE-2016-7153 | The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack. | 2 | 5 | Medium | 2017-01-19 | 2016-11-28 | View |
Page 16360 of 17672, showing 5 records out of 88360 total, starting on record 81796, ending on 81800