|
265261
|
6.8 |
MEDIUM
Physics
|
samsung
|
galaxy_s6_firmware galaxy_note_3_firmware galaxy_s4_mini_firmware galaxy_s4_mini_lte_firmware galaxy_s4_firmware
|
Samsung SM-G920F build G920FXXU2COH2 (Galaxy S6), SM-N9005 build N9005XXUGBOK6 (Galaxy Note 3), GT-I9192 build I9192XXUBNB1 (Galaxy S4 mini), GT-I9195 build I9195XXUCOL1 (Galaxy S4 mini LTE), and GT-…
|
CWE-284
Improper Access Control
|
CVE-2016-4031
|
2024-11-21 11:51 |
2017-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265262
|
6.8 |
MEDIUM
Physics
|
samsung
|
galaxy_s6_firmware galaxy_note_3_firmware galaxy_s4_mini_firmware galaxy_s4_mini_lte_firmware galaxy_s4_firmware
|
Samsung SM-G920F build G920FXXU2COH2 (Galaxy S6), SM-N9005 build N9005XXUGBOK6 (Galaxy Note 3), GT-I9192 build I9192XXUBNB1 (Galaxy S4 mini), GT-I9195 build I9195XXUCOL1 (Galaxy S4 mini LTE), and GT-…
|
CWE-284
Improper Access Control
|
CVE-2016-4030
|
2024-11-21 11:51 |
2017-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265263
|
6.1 |
MEDIUM
Network
|
opensuse roundcube
|
leap opensuse roundcube_webmail webmail
|
Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG, a different vulnera…
|
CWE-79
Cross-site Scripting
|
CVE-2016-4068
|
2024-11-21 11:51 |
2017-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265264
|
9.8 |
CRITICAL
Network
|
ktools
|
photostore
|
SQL injection vulnerability in the mgr.login.php file in Ktools.net Photostore before 4.7.5 allows remote attackers to execute arbitrary SQL commands via the email parameter in a recover_login action.
|
CWE-89
SQL Injection
|
CVE-2016-4337
|
2024-11-21 11:51 |
2017-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265265
|
6.1 |
MEDIUM
Network
|
jivesoftware
|
jive
|
Jive before 2016.3.1 has an open redirect from the external-link.jspa page.
|
CWE-601
Open Redirect
|
CVE-2016-4334
|
2024-11-21 11:51 |
2017-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265266
|
4.3 |
MEDIUM
Network
|
atlassian
|
bitbucket
|
Atlassian Bitbucket Server before 4.7.1 allows remote attackers to read the first line of an arbitrary file via a directory traversal attack on the pull requests resource.
|
CWE-22
Path Traversal
|
CVE-2016-4320
|
2024-11-21 11:51 |
2017-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265267
|
8.8 |
HIGH
Network
|
atlassian
|
jira
|
Atlassian JIRA Server before 7.1.9 has CSRF in auditing/settings.
|
CWE-352
Origin Validation Error
|
CVE-2016-4319
|
2024-11-21 11:51 |
2017-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265268
|
4.8 |
MEDIUM
Network
|
atlassian
|
jira
|
Atlassian JIRA Server before 7.1.9 has XSS in project/ViewDefaultProjectRoleActors.jspa via a role name.
|
CWE-79
Cross-site Scripting
|
CVE-2016-4318
|
2024-11-21 11:51 |
2017-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265269
|
5.4 |
MEDIUM
Network
|
atlassian
|
confluence
|
Atlassian Confluence Server before 5.9.11 has XSS on the viewmyprofile.action page.
|
CWE-79
Cross-site Scripting
|
CVE-2016-4317
|
2024-11-21 11:51 |
2017-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265270
|
4.9 |
MEDIUM
Network
|
plone
|
plone
|
Chameleon (five.pt) in Plone 5.0rc1 through 5.1a1 allows remote authenticated users to bypass Restricted Python by leveraging permissions to create or edit templates.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-4043
|
2024-11-21 11:51 |
2017-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|