|
266381
|
7.5 |
HIGH
Network
|
redhat debian
|
libvirt debian_linux
|
libvirt-domain.c in libvirt before 1.3.1 supports virDomainGetTime API calls by guest agents with an RO connection, even though an RW connection was supposed to be required, a different vulnerability…
|
CWE-254
7PK - Security Features
|
CVE-2016-10746
|
2024-11-21 11:44 |
2019-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266382
|
8.6 |
HIGH
Network
|
palletsprojects
|
jinja
|
In Pallets Jinja before 2.8.1, str.format allows a sandbox escape.
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2016-10745
|
2024-11-21 11:44 |
2019-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266383
|
6.1 |
MEDIUM
Network
|
select2
|
select2
|
In Select2 through 4.0.5, as used in Snipe-IT and other products, rich selectlists allow XSS. This affects use cases with Ajax remote data loading when HTML templates are used to display listbox data.
|
CWE-79
Cross-site Scripting
|
CVE-2016-10744
|
2024-11-21 11:44 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266384
|
7.5 |
HIGH
Network
|
w1.fi
|
hostapd
|
hostapd before 2.6 does not prevent use of the low-quality PRNG that is reached by an os_random() function call.
|
CWE-332
Insufficient Entropy in PRNG
|
CVE-2016-10743
|
2024-11-21 11:44 |
2019-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266385
|
6.1 |
MEDIUM
Network
|
zabbix debian
|
zabbix debian_linux
|
Zabbix before 2.2.21rc1, 3.x before 3.0.13rc1, 3.1.x and 3.2.x before 3.2.10rc1, and 3.3.x and 3.4.x before 3.4.4rc1 allows open redirect via the request parameter.
|
CWE-601
Open Redirect
|
CVE-2016-10742
|
2024-11-21 11:44 |
2019-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266386
|
4.7 |
MEDIUM
Local
|
linux debian
|
linux_kernel debian_linux
|
In the Linux kernel before 4.9.3, fs/xfs/xfs_aops.c allows local users to cause a denial of service (system crash) because there is a race condition between direct and memory-mapped I/O (associated w…
|
CWE-362
Race Condition
|
CVE-2016-10741
|
2024-11-21 11:44 |
2019-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266387
|
4.9 |
MEDIUM
Network
|
atlassian
|
crowd
|
Various resources in Atlassian Crowd before version 2.10.1 allow remote attackers with administration rights to learn the passwords of configured LDAP directories by examining the responses to reques…
|
CWE-200
Information Exposure
|
CVE-2016-10740
|
2024-11-21 11:44 |
2019-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266388
|
5.3 |
MEDIUM
Local
|
gnu opensuse
|
glibc leap
|
In the GNU C Library (aka glibc or libc6) through 2.28, the getaddrinfo function would successfully parse a string that contained an IPv4 address followed by whitespace and arbitrary characters, whic…
|
CWE-20
Improper Input Validation
|
CVE-2016-10739
|
2024-11-21 11:44 |
2019-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266389
|
8.8 |
HIGH
Network
|
castlamp
|
zenbership
|
Zenbership v107 has CSRF via admin/cp-functions/event-add.php.
|
CWE-352
Origin Validation Error
|
CVE-2016-10738
|
2024-11-21 11:44 |
2019-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266390
|
5.4 |
MEDIUM
Network
|
s9y
|
serendipity
|
Serendipity 2.0.4 has XSS via the serendipity_admin.php serendipity[body] parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2016-10737
|
2024-11-21 11:44 |
2019-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|