|
269361
|
7.8 |
HIGH
Local
|
foxitsoftware
|
foxit_reader
|
Heap-based buffer overflow in the CreateFXPDFConvertor function in ConvertToPdf_x86.dll in Foxit Reader 7.3.4.311 allows remote attackers to execute arbitrary code via a large SamplesPerPixel value i…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-3740
|
2024-11-21 11:50 |
2017-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269362
|
9.8 |
CRITICAL
Network
|
modified
|
ecommerce_shopsoftware
|
Multiple SQL injection vulnerabilities in modified eCommerce Shopsoftware 2.0.0.0 revision 9678, when the easybill-module is not installed, allow remote attackers to execute arbitrary SQL commands vi…
|
CWE-89
SQL Injection
|
CVE-2016-3694
|
2024-11-21 11:50 |
2017-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269363
|
8.8 |
HIGH
Network
|
libjpeg-turbo redhat debian canonical
|
libjpeg-turbo enterprise_linux debian_linux ubuntu_linux
|
The cjpeg utility in libjpeg allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or execute arbitrary code via a crafted file.
|
CWE-476
NULL Pointer Dereference
|
CVE-2016-3616
|
2024-11-21 11:50 |
2017-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269364
|
4.7 |
MEDIUM
Local
|
sap
|
download_manager
|
SAP Download Manager 2.1.142 and earlier generates an encryption key from a small key space on Windows and Mac systems, which allows context-dependent attackers to obtain sensitive configuration info…
|
CWE-255 CWE-798
Credentials Management Use of Hard-coded Credentials
|
CVE-2016-3685
|
2024-11-21 11:50 |
2016-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269365
|
4.7 |
MEDIUM
Local
|
sap
|
download_manager
|
SAP Download Manager 2.1.142 and earlier uses a hardcoded encryption key to protect stored data, which allows context-dependent attackers to obtain sensitive configuration information by leveraging k…
|
NVD-CWE-Other
|
CVE-2016-3684
|
2024-11-21 11:50 |
2016-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269366
|
5.5 |
MEDIUM
Local
|
google
|
android
|
An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver in Android before 2016-11-05 could enable a local m…
|
CWE-200
Information Exposure
|
CVE-2016-3907
|
2024-11-21 11:50 |
2016-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269367
|
5.5 |
MEDIUM
Local
|
google
|
android
|
An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver in Android before 2016-11-05 could enable a local m…
|
CWE-200
Information Exposure
|
CVE-2016-3906
|
2024-11-21 11:50 |
2016-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269368
|
7.8 |
HIGH
Local
|
google
|
android
|
An elevation of privilege vulnerability in the Qualcomm bus driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-3904
|
2024-11-21 11:50 |
2016-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269369
|
2.4 |
LOW
Network
|
oracle
|
database_server
|
Unspecified vulnerability in the RDBMS Security and SQL*Plus components in Oracle Database Server 11.2.0.4 and 12.1.0.2 allows remote administrators to affect confidentiality via vectors related to D…
|
CWE-200
Information Exposure
|
CVE-2016-3562
|
2024-11-21 11:50 |
2016-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269370
|
9.8 |
CRITICAL
Network
|
oracle
|
weblogic_server
|
Unspecified vulnerability in the Oracle Web Services component in Oracle Fusion Middleware 11.1.1.7.0, 11.1.1.9.0, 12.1.3.0.0, and 12.2.1.0.0 allows remote attackers to affect confidentiality, integr…
|
NVD-CWE-noinfo
|
CVE-2016-3551
|
2024-11-21 11:50 |
2016-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|