|
268801
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In all Android releases from CAF using the Linux kernel, a dynamically-protected DDR region could potentially get overwritten.
|
CWE-284
Improper Access Control
|
CVE-2016-10334
|
2024-11-21 11:43 |
2017-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268802
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In all Android releases from CAF using the Linux kernel, a sensitive system call was allowed to be called by HLOS.
|
CWE-284
Improper Access Control
|
CVE-2016-10333
|
2024-11-21 11:43 |
2017-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268803
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In all Android releases from CAF using the Linux kernel, stack protection was not enabled for secure applications.
|
CWE-254
7PK - Security Features
|
CVE-2016-10332
|
2024-11-21 11:43 |
2017-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268804
|
7.0 |
HIGH
Local
|
google
|
android
|
In TrustZone in all Android releases from CAF using the Linux kernel, a Time-of-Check Time-of-Use Race Condition vulnerability could potentially exist.
|
CWE-362
Race Condition
|
CVE-2016-10297
|
2024-11-21 11:43 |
2017-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268805
|
7.2 |
HIGH
Network
|
virtuemart
|
virtuemart
|
The VirtueMart com_virtuemart component 3.0.14 for Joomla! allows SQL injection by remote authenticated administrators via the virtuemart_paymentmethod_id or virtuemart_shipmentmethod_id parameter to…
|
CWE-89
SQL Injection
|
CVE-2016-10379
|
2024-11-21 11:43 |
2017-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268806
|
7.2 |
HIGH
Network
|
e107
|
e107
|
e107 2.1.1 allows SQL injection by remote authenticated administrators via the pagelist parameter to e107_admin/menus.php, related to the menuSaveVisibility function.
|
CWE-89
SQL Injection
|
CVE-2016-10378
|
2024-11-21 11:43 |
2017-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268807
|
8.8 |
HIGH
Adjacent
|
openvswitch
|
openvswitch
|
In Open vSwitch (OvS) 2.5.0, a malformed IP packet can cause the switch to read past the end of the packet buffer due to an unsigned integer underflow in `lib/flow.c` in the function `miniflow_extrac…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-10377
|
2024-11-21 11:43 |
2017-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268808
|
4.5 |
MEDIUM
Network
|
gajim
|
gajim
|
Gajim through 0.16.7 unconditionally implements the "XEP-0146: Remote Controlling Clients" extension. This can be abused by malicious XMPP servers to, for example, extract plaintext from OTR encrypte…
|
CWE-310
Cryptographic Issues
|
CVE-2016-10376
|
2024-11-21 11:43 |
2017-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268809
|
9.8 |
CRITICAL
Network
|
yodl_project
|
yodl
|
Yodl before 3.07.01 has a Buffer Over-read in the queue_push function in queue/queuepush.c.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-10375
|
2024-11-21 11:43 |
2017-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268810
|
7.5 |
HIGH
Network
|
vanillaforums
|
vanilla
|
The from method in library/core/class.email.php in Vanilla Forums before 2.3.1 allows remote attackers to spoof the email domain in sent messages and potentially obtain sensitive information via a cr…
|
CWE-200
Information Exposure
|
CVE-2016-10073
|
2024-11-21 11:43 |
2017-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|