NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
23430  CVE-2015-1042  The string_sanitize_url function in core/string_api.php in MantisBT 1.2.0a3 through 1.2.18 uses an incorrect regular expression, which allows remote attackers to conduct open redirect and phishing attacks via a URL with a ":/" (colon slash) separator in the return parameter to login_page.php, a different vulnerability than CVE-2014-6316.    5.8  Medium  2017-01-19  2015-11-27  View
36008  CVE-2014-9272  The string_insert_href function in MantisBT 1.2.0a1 through 1.2.x before 1.2.18 does not properly validate the URL protocol, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the javascript:// protocol.    4.3  Medium  2017-01-19  2017-01-02  View
24230  CVE-2015-2059  The stringprep_utf8_to_ucs4 function in libin before 1.31, as used in jabberd2, allows context-dependent attackers to read system memory and possibly have other unspecified impact via invalid UTF-8 characters in a string, which triggers an out-of-bounds read.    7.5  High  2017-01-19  2016-11-30  View
21086  CVE-2016-6263  The stringprep_utf8_nfkc_normalize function in lib/nfkc.c in libidn before 1.33 allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via crafted UTF-8 data.    Medium  2017-01-19  2016-11-28  View
83891  CVE-2015-4556  The string-translate* procedure in the data-structures unit in CHICKEN before 4.10.0 allows remote attackers to cause a denial of service (crash).          2017-03-29  2017-03-29  View

Page 3004 of 17672, showing 5 records out of 88360 total, starting on record 15016, ending on 15020

Actions