|
265571
|
6.5 |
MEDIUM
Network
|
gnu debian
|
cpio debian_linux
|
The cpio_safer_name_suffix function in util.c in cpio 2.11 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted cpio file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-2037
|
2024-11-21 11:47 |
2016-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265572
|
5.4 |
MEDIUM
Network
|
phpmyadmin fedoraproject
|
phpmyadmin fedora
|
Cross-site scripting (XSS) vulnerability in the SQL editor in phpMyAdmin 4.5.x before 4.5.4 allows remote authenticated users to inject arbitrary web script or HTML via a SQL query that triggers JSON…
|
CWE-79
Cross-site Scripting
|
CVE-2016-2045
|
2024-11-21 11:47 |
2016-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265573
|
5.3 |
MEDIUM
Network
|
fedoraproject phpmyadmin
|
fedora phpmyadmin
|
libraries/sql-parser/autoload.php in the SQL parser in phpMyAdmin 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an e…
|
CWE-200
Information Exposure
|
CVE-2016-2044
|
2024-11-21 11:47 |
2016-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265574
|
5.4 |
MEDIUM
Network
|
fedoraproject opensuse phpmyadmin
|
fedora leap opensuse phpmyadmin
|
Cross-site scripting (XSS) vulnerability in the goToFinish1NF function in js/normalization.js in phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote authenticated users to inject ar…
|
CWE-79
Cross-site Scripting
|
CVE-2016-2043
|
2024-11-21 11:47 |
2016-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265575
|
5.3 |
MEDIUM
Network
|
opensuse fedoraproject phpmyadmin
|
leap opensuse fedora phpmyadmin
|
phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request to (1) libraries/phpseclib/Crypt/AES.php or (2) libraries/phpsecl…
|
CWE-200
Information Exposure
|
CVE-2016-2042
|
2024-11-21 11:47 |
2016-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265576
|
7.5 |
HIGH
Network
|
fedoraproject phpmyadmin opensuse
|
fedora phpmyadmin leap opensuse
|
libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not use a constant-time algorithm for comparing CSRF tokens, which makes it easier fo…
|
CWE-254
7PK - Security Features
|
CVE-2016-2041
|
2024-11-21 11:47 |
2016-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265577
|
5.4 |
MEDIUM
Network
|
fedoraproject opensuse phpmyadmin
|
fedora leap opensuse phpmyadmin
|
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 allow remote authenticated users to inject arbitrary web script…
|
CWE-79
Cross-site Scripting
|
CVE-2016-2040
|
2024-11-21 11:47 |
2016-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265578
|
5.3 |
MEDIUM
Network
|
opensuse phpmyadmin fedoraproject
|
leap opensuse phpmyadmin fedora
|
libraries/session.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not properly generate CSRF token values, which allows remote attackers to bypass int…
|
CWE-200
Information Exposure
|
CVE-2016-2039
|
2024-11-21 11:47 |
2016-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265579
|
5.3 |
MEDIUM
Network
|
phpmyadmin fedoraproject opensuse
|
phpmyadmin fedora leap opensuse
|
phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error…
|
CWE-200
Information Exposure
|
CVE-2016-2038
|
2024-11-21 11:47 |
2016-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265580
|
7.5 |
HIGH
Network
|
phpmyadmin
|
phpmyadmin
|
The suggestPassword function in js/functions.js in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 relies on the Math.random JavaScript function, which makes it easie…
|
CWE-255 CWE-254
Credentials Management 7PK - Security Features
|
CVE-2016-1927
|
2024-11-21 11:47 |
2016-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|