|
265971
|
7.5 |
HIGH
Network
|
drupal
|
drupal
|
The user password reset form in Drupal 8.x before 8.2.3 allows remote attackers to conduct cache poisoning attacks by leveraging failure to specify a correct cache context.
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2016-9450
|
2024-11-21 12:01 |
2016-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265972
|
4.3 |
MEDIUM
Network
|
drupal
|
drupal
|
The taxonomy module in Drupal 7.x before 7.52 and 8.x before 8.2.3 might allow remote authenticated users to obtain sensitive information about taxonomy terms by leveraging inconsistent naming of acc…
|
CWE-200
Information Exposure
|
CVE-2016-9449
|
2024-11-21 12:01 |
2016-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265973
|
5.5 |
MEDIUM
Local
|
samsung
|
samsung_mobile
|
The mDNIe system service on Samsung Mobile S7 devices with M(6.0) software does not properly restrict setmDNIeScreenCurtain API calls, enabling attackers to control a device's screen. This can be exp…
|
CWE-200
Information Exposure
|
CVE-2016-9567
|
2024-11-21 12:01 |
2016-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265974
|
7.5 |
HIGH
Network
|
sap
|
netweaver_application_server_java
|
SAP NetWeaver AS JAVA 7.4 allows remote attackers to cause a Denial of Service (null pointer exception and icman outage) via an HTTPS request to the sap.com~P4TunnelingApp!web/myServlet URI, aka SAP …
|
CWE-476
NULL Pointer Dereference
|
CVE-2016-9562
|
2024-11-21 12:01 |
2016-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265975
|
9.8 |
CRITICAL
Network
|
libtiff
|
libtiff
|
tools/tiffcp.c in libtiff 4.0.6 has an out-of-bounds write on tiled images with odd tile width versus image width. Reported as MSVR 35103, aka "cpStripToTile heap-buffer-overflow."
|
CWE-119 CWE-787
Incorrect Access of Indexable Resource ('Range Error') Out-of-bounds Write
|
CVE-2016-9540
|
2024-11-21 12:01 |
2016-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265976
|
9.8 |
CRITICAL
Network
|
libtiff
|
libtiff
|
tools/tiffcrop.c in libtiff 4.0.6 has an out-of-bounds read in readContigTilesIntoBuffer(). Reported as MSVR 35092.
|
CWE-119 CWE-125
Incorrect Access of Indexable Resource ('Range Error') Out-of-bounds Read
|
CVE-2016-9539
|
2024-11-21 12:01 |
2016-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265977
|
9.8 |
CRITICAL
Network
|
libtiff
|
libtiff
|
tools/tiffcrop.c in libtiff 4.0.6 reads an undefined buffer in readContigStripsIntoBuffer() because of a uint16 integer overflow. Reported as MSVR 35100.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2016-9538
|
2024-11-21 12:01 |
2016-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265978
|
9.8 |
CRITICAL
Network
|
libtiff
|
libtiff
|
tools/tiffcrop.c in libtiff 4.0.6 has out-of-bounds write vulnerabilities in buffers. Reported as MSVR 35093, MSVR 35096, and MSVR 35097.
|
CWE-119 CWE-787
Incorrect Access of Indexable Resource ('Range Error') Out-of-bounds Write
|
CVE-2016-9537
|
2024-11-21 12:01 |
2016-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265979
|
9.8 |
CRITICAL
Network
|
libtiff
|
libtiff
|
tools/tiff2pdf.c in libtiff 4.0.6 has out-of-bounds write vulnerabilities in heap allocated buffers in t2p_process_jpeg_strip(). Reported as MSVR 35098, aka "t2p_process_jpeg_strip heap-buffer-overfl…
|
CWE-119 CWE-787
Incorrect Access of Indexable Resource ('Range Error') Out-of-bounds Write
|
CVE-2016-9536
|
2024-11-21 12:01 |
2016-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265980
|
9.8 |
CRITICAL
Network
|
libtiff
|
libtiff
|
tif_predict.h and tif_predict.c in libtiff 4.0.6 have assertions that can lead to assertion failures in debug mode, or buffer overflows in release mode, when dealing with unusual tile size like YCbCr…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-9535
|
2024-11-21 12:01 |
2016-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|