|
256971
|
7.5 |
HIGH
Network
|
redhat debian mozilla
|
enterprise_linux_server enterprise_linux_workstation debian_linux firefox firefox_esr thunderbird
|
Memory corruption resulting in a potentially exploitable crash during WebGL functions using a vector constructor with a varying array within libGLES. This vulnerability affects Firefox < 50.1, Firefo…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-9897
|
2024-11-21 12:01 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256972
|
7.5 |
HIGH
Network
|
debian redhat mozilla
|
debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation enterprise_linux enterprise_linux_server_aus enterprise_linux_server_eus thunderbird
|
External resources that should be blocked when loaded by SVG images can bypass security restrictions through the use of "data:" URLs. This could allow for cross-domain data leakage. This vulnerabilit…
|
CWE-254
7PK - Security Features
|
CVE-2016-9900
|
2024-11-21 12:01 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256973
|
8.1 |
HIGH
Network
|
mozilla
|
firefox
|
Use-after-free while manipulating the "navigator" object within WebVR. Note: WebVR is not currently enabled by default. This vulnerability affects Firefox < 50.1.
|
CWE-416
Use After Free
|
CVE-2016-9896
|
2024-11-21 12:01 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256974
|
6.1 |
MEDIUM
Network
|
debian redhat mozilla
|
debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation enterprise_linux enterprise_linux_server_aus enterprise_linux_server_eus thunderbird
|
Event handlers on "marquee" elements were executed despite a strict Content Security Policy (CSP) that disallowed inline JavaScript. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and…
|
CWE-254
7PK - Security Features
|
CVE-2016-9895
|
2024-11-21 12:01 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256975
|
7.5 |
HIGH
Network
|
mozilla
|
firefox
|
A buffer overflow in SkiaGl caused when a GrGLBuffer is truncated during allocation. Later writers will overflow the buffer, resulting in a potentially exploitable crash. This vulnerability affects F…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-9894
|
2024-11-21 12:01 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256976
|
9.8 |
CRITICAL
Network
|
debian redhat mozilla
|
debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation enterprise_linux enterprise_linux_server_aus enterprise_linux_server_eus thunderbird
|
Memory safety bugs were reported in Thunderbird 45.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbit…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-9893
|
2024-11-21 12:01 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256977
|
6.1 |
MEDIUM
Network
|
manageengine
|
applications_manager
|
ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from a Reflected Cross-Site Scripting vulnerability. Applications Manager is prone to a Cross-Site Scripting vulnerabili…
|
CWE-79
Cross-site Scripting
|
CVE-2016-9490
|
2024-11-21 12:01 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256978
|
9.8 |
CRITICAL
Network
|
manageengine
|
applications_manager
|
ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from remote SQL injection vulnerabilities. An unauthenticated attacker is able to access the URL /servlet/MenuHandlerSer…
|
CWE-89
SQL Injection
|
CVE-2016-9488
|
2024-11-21 12:01 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256979
|
8.8 |
HIGH
Network
|
qemu debian
|
qemu debian_linux
|
Qemu before version 2.9 is vulnerable to an improper link following when built with the VirtFS. A privileged user inside guest could use this flaw to access host file system beyond the shared folder …
|
CWE-59
Link Following
|
CVE-2016-9602
|
2024-11-21 12:01 |
2018-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256980
|
6.5 |
MEDIUM
Network
|
openstack redhat
|
puppet-swift openstack
|
puppet-swift before versions 8.2.1, 9.4.4 is vulnerable to an information-disclosure in Red Hat OpenStack Platform director's installation of Object Storage (swift). During installation, the Puppet s…
|
CWE-200
Information Exposure
|
CVE-2016-9590
|
2024-11-21 12:01 |
2018-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|