|
266231
|
5.3 |
MEDIUM
Network
|
exponentcms
|
exponent_cms
|
framework/modules/addressbook/controllers/addressController.php in Exponent CMS v2.4.0 allows remote attackers to read user information via a modified id number, as demonstrated by address/edit/id/1,…
|
CWE-200
Information Exposure
|
CVE-2016-9285
|
2024-11-21 12:00 |
2016-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266232
|
5.3 |
MEDIUM
Network
|
exponentcms
|
exponent_cms
|
getUsersByJSON in framework/modules/users/controllers/usersController.php in Exponent CMS v2.4.0 allows remote attackers to read user information via users/getUsersByJSON/sort/ and a trailing string.
|
CWE-200
Information Exposure
|
CVE-2016-9284
|
2024-11-21 12:00 |
2016-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266233
|
7.5 |
HIGH
Network
|
exponentcms
|
exponent_cms
|
SQL Injection in framework/core/subsystems/expRouter.php in Exponent CMS v2.4.0 allows remote attackers to read database information via address/addContentToSearch/id/ and a trailing string, related …
|
CWE-89
SQL Injection
|
CVE-2016-9283
|
2024-11-21 12:00 |
2016-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266234
|
7.5 |
HIGH
Network
|
exponentcms
|
exponent_cms
|
SQL Injection in framework/modules/search/controllers/searchController.php in Exponent CMS v2.4.0 allows remote attackers to read database information via action=search&module=search with the search_…
|
CWE-89
SQL Injection
|
CVE-2016-9282
|
2024-11-21 12:00 |
2016-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266235
|
7.5 |
HIGH
Network
|
samsung
|
samsung_mobile
|
Integer overflow in SystemUI in KK(4.4) and L(5.0/5.1) on Samsung Note devices allows attackers to cause a denial of service (UI restart) via vectors involving APIs and an activity that computes an o…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2016-9277
|
2024-11-21 12:00 |
2016-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266236
|
7.8 |
HIGH
Local
|
git_for_windows_project
|
git_for_windows
|
Untrusted search path vulnerability in Git 1.x for Windows allows local users to gain privileges via a Trojan horse git.exe file in the current working directory. NOTE: 2.x is unaffected.
|
CWE-426
Untrusted Search Path
|
CVE-2016-9274
|
2024-11-21 12:00 |
2016-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266237
|
9.1 |
CRITICAL
Network
|
exponentcms
|
exponent_cms
|
A Blind SQL Injection Vulnerability in Exponent CMS through 2.4.0, with the rerank array parameter, can lead to site database information disclosure and denial of service.
|
CWE-89
SQL Injection
|
CVE-2016-9272
|
2024-11-21 12:00 |
2016-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266238
|
7.2 |
HIGH
Network
|
dotclear
|
dotclear
|
Unrestricted file upload vulnerability in the Blog appearance in the "Install or upgrade manually" module in Dotclear through 2.10.4 allows remote authenticated super-administrators to execute arbitr…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2016-9268
|
2024-11-21 12:00 |
2016-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266239
|
8.8 |
HIGH
Local
|
nvidia
|
geforce_experience
|
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA GeForce Experience R340 before GFE 2.11.4.125 and R375 before GFE 3.1.0.52 contains a vulnerability in the kernel mode layer (nvstreamkms.sys)…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-8812
|
2024-11-21 12:00 |
2016-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266240
|
7.8 |
HIGH
Local
|
nvidia
|
gpu_driver
|
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-8811
|
2024-11-21 12:00 |
2016-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|