|
266141
|
7.2 |
HIGH
Network
|
opencart
|
opencart
|
SQL injection vulnerability in the updateAmazonOrderTracking function in upload/admin/model/openbay/amazon.php in OpenCart before version 2.3.0.0 allows remote authenticated administrators to execute…
|
CWE-89
SQL Injection
|
CVE-2016-10509
|
2024-11-21 11:44 |
2017-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266142
|
6.1 |
MEDIUM
Network
|
phpthumb_project
|
phpthumb
|
Multiple cross-site scripting (XSS) vulnerabilities in phpThumb() before 1.7.14 allow remote attackers to inject arbitrary web script or HTML via parameters in demo/phpThumb.demo.showpic.php.
|
CWE-79
Cross-site Scripting
|
CVE-2016-10508
|
2024-11-21 11:44 |
2017-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266143
|
6.5 |
MEDIUM
Network
|
uclouvain
|
openjpeg
|
Integer overflow vulnerability in the bmp24toimage function in convertbmp.c in OpenJPEG before 2.2.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application …
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2016-10507
|
2024-11-21 11:44 |
2017-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266144
|
6.5 |
MEDIUM
Network
|
uclouvain
|
openjpeg
|
Division-by-zero vulnerabilities in the functions opj_pi_next_cprl, opj_pi_next_pcrl, and opj_pi_next_rpcl in pi.c in OpenJPEG before 2.2.0 allow remote attackers to cause a denial of service (applic…
|
CWE-369
Divide By Zero
|
CVE-2016-10506
|
2024-11-21 11:44 |
2017-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266145
|
6.5 |
MEDIUM
Network
|
uclouvain
|
openjpeg
|
NULL pointer dereference vulnerabilities in the imagetopnm function in convert.c, sycc444_to_rgb function in color.c, color_esycc_to_rgb function in color.c, and sycc422_to_rgb function in color.c in…
|
CWE-476
NULL Pointer Dereference
|
CVE-2016-10505
|
2024-11-21 11:44 |
2017-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266146
|
6.5 |
MEDIUM
Network
|
uclouvain
|
openjpeg
|
Heap-based buffer overflow vulnerability in the opj_mqc_byteout function in mqc.c in OpenJPEG before 2.2.0 allows remote attackers to cause a denial of service (application crash) via a crafted bmp f…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-10504
|
2024-11-21 11:44 |
2017-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266147
|
4.3 |
MEDIUM
Network
|
ibm
|
sametime
|
IBM Sametime Meeting Server 8.5.2 and 9.0 could allow an authenticated and invited user of Sametime meeting to lower any or all hands in an e-meeting, thus spoofing results of votes in the meeting. I…
|
CWE-20
Improper Input Validation
|
CVE-2016-10503
|
2024-11-21 11:44 |
2017-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266148
|
6.1 |
MEDIUM
Network
|
apostrophecms
|
sanitize-html
|
sanitize-html before 1.4.3 has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2016-1000237
|
2024-11-21 11:43 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266149
|
6.1 |
MEDIUM
Network
|
smartbear redhat
|
swagger-ui openshift jboss_fuse
|
swagger-ui has XSS in key names
|
CWE-79
Cross-site Scripting
|
CVE-2016-1000229
|
2024-11-21 11:43 |
2019-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266150
|
4.4 |
MEDIUM
Network
|
cookie-signature_project debian
|
cookie-signature debian_linux
|
Node-cookie-signature before 1.0.6 is affected by a timing attack due to the type of comparison used.
|
CWE-362
Race Condition
|
CVE-2016-1000236
|
2024-11-21 11:43 |
2019-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|