|
267381
|
8.8 |
HIGH
Network
|
pivotal
|
spring_security_oauth
|
When processing authorization requests using the whitelabel views in Spring Security OAuth 2.0.0 to 2.0.9 and 1.0.0 to 1.0.5, the response_type parameter value was executed as Spring SpEL which enabl…
|
CWE-19
Data Processing Errors
|
CVE-2016-4977
|
2024-11-21 11:53 |
2017-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267382
|
7.5 |
HIGH
Network
|
pivotal_software vmware
|
spring_framework spring_security
|
Both Spring Security 3.2.x, 4.0.x, 4.1.0 and the Spring Framework 3.2.x, 4.0.x, 4.1.x, 4.2.x rely on URL pattern mappings for authorization and for mapping requests to controllers respectively. Diffe…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-5007
|
2024-11-21 11:53 |
2017-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267383
|
9.8 |
CRITICAL
Network
|
google opensuse debian redhat fedoraproject
|
chrome leap opensuse debian_linux enterprise_linux_server_supplementary enterprise_linux_workstation_supplementary fedora
|
Multiple unspecified vulnerabilities in Google Chrome before 53.0.2785.143 allow remote attackers to cause a denial of service or possibly have other impact via unknown vectors.
|
CWE-20
Improper Input Validation
|
CVE-2016-5178
|
2024-11-21 11:53 |
2017-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267384
|
8.8 |
HIGH
Network
|
google opensuse debian redhat fedoraproject
|
chrome leap opensuse debian_linux enterprise_linux_server_supplementary enterprise_linux_workstation_supplementary fedora
|
Use-after-free vulnerability in V8 in Google Chrome before 53.0.2785.143 allows remote attackers to cause a denial of service (crash) or possibly have unspecified other impact via unknown vectors.
|
CWE-416
Use After Free
|
CVE-2016-5177
|
2024-11-21 11:53 |
2017-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267385
|
9.8 |
CRITICAL
Network
|
wp-olivecart
|
olivecart olivecartpro
|
SQL injection vulnerability in the WP-OliveCart versions prior to 3.1.3 and WP-OliveCartPro versions prior to 3.1.8 allows attackers with administrator rights to execute arbitrary SQL commands via un…
|
CWE-89
SQL Injection
|
CVE-2016-4905
|
2024-11-21 11:53 |
2017-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267386
|
8.8 |
HIGH
Network
|
wp-olivecart
|
olivecart olivecartpro
|
Cross-site request forgery (CSRF) vulnerability in WP-OliveCart versions prior to 3.1.3 and WP-OliveCartPro versions prior to 3.1.8 allows remote attackers to hijack the authentication of a user to p…
|
CWE-352
Origin Validation Error
|
CVE-2016-4904
|
2024-11-21 11:53 |
2017-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267387
|
6.1 |
MEDIUM
Network
|
wp-olivecart
|
olivecart olivecartpro
|
Cross-site scripting vulnerability in WP-OliveCart versions prior to 3.1.3 and WP-OliveCartPro versions prior to 3.1.8 allows remote attackers to inject arbitrary web script or HTML via unspecified v…
|
CWE-79
Cross-site Scripting
|
CVE-2016-4903
|
2024-11-21 11:53 |
2017-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267388
|
7.8 |
HIGH
Local
|
national_tax_agency
|
e-tax
|
Untrusted search path vulnerability in The installer of e-Tax Software all versions allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory.
|
CWE-426
Untrusted Search Path
|
CVE-2016-4901
|
2024-11-21 11:53 |
2017-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267389
|
7.8 |
HIGH
Local
|
evernote
|
evernote
|
Untrusted search path vulnerability in Evernote for Windows versions prior to 6.3 allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory.
|
CWE-426
Untrusted Search Path
|
CVE-2016-4900
|
2024-11-21 11:53 |
2017-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267390
|
4.3 |
MEDIUM
Adjacent
|
toshiba
|
flashair
|
The Toshiba FlashAir SD-WD/WC series Class 6 model with firmware version 1.00.04 and later, FlashAir SD-WD/WC series Class 10 model W-02 with firmware version 2.00.02 and later, FlashAir SD-WE series…
|
CWE-287
Improper Authentication
|
CVE-2016-4863
|
2024-11-21 11:53 |
2017-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|