|
257341
|
9.8 |
CRITICAL
Network
|
exponentcms
|
exponent_cms
|
Exponent CMS version 2.3.9 suffers from a Object Injection vulnerability in framework/modules/core/controllers/expCatController.php related to change_cats.
|
CWE-74
Injection
|
CVE-2016-8899
|
2024-11-21 12:00 |
2019-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257342
|
9.8 |
CRITICAL
Network
|
exponentcms
|
exponent_cms
|
Exponent CMS version 2.3.9 suffers from a sql injection vulnerability in framework/modules/help/controllers/helpController.php.
|
CWE-89
SQL Injection
|
CVE-2016-8897
|
2024-11-21 12:00 |
2019-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257343
|
9.8 |
CRITICAL
Network
|
b2evolution
|
b2evolution
|
b2evolution 6.7.6 suffer from an Object Injection vulnerability in /htsrv/call_plugin.php.
|
CWE-74
Injection
|
CVE-2016-8901
|
2024-11-21 12:00 |
2019-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257344
|
7.5 |
HIGH
Network
|
microfocus
|
netiq_edirectory
|
NetIQ eDirectory versions prior to 9.0.2, under some circumstances, could be susceptible to downgrade of communication security.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-9166
|
2024-11-21 12:00 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257345
|
7.8 |
HIGH
Local
|
mozilla
|
firefox
|
A use-after-free in nsINode::ReplaceOrInsertBefore during DOM operations resulting in potentially exploitable crashes. This vulnerability affects Firefox < 50.
|
CWE-416
Use After Free
|
CVE-2016-9069
|
2024-11-21 12:00 |
2018-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257346
|
8.8 |
HIGH
Network
|
processmaker
|
processmaker
|
A code execution vulnerability exists in ProcessMaker Enterprise Core 3.0.1.7-community. A specially crafted web request can cause unsafe deserialization potentially resulting in PHP code being execu…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2016-9045
|
2024-11-21 12:00 |
2018-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257347
|
7.4 |
HIGH
Network
|
processmaker
|
processmaker
|
Multiple exploitable SQL Injection vulnerabilities exists in ProcessMaker Enterprise Core 3.0.1.7-community. Specially crafted web requests can cause SQL injections. An attacker can send a web reques…
|
CWE-89
SQL Injection
|
CVE-2016-9048
|
2024-11-21 12:00 |
2018-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257348
|
8.8 |
HIGH
Network
|
informationbuilders
|
webfocus
|
An exploitable command execution vulnerability exists in Information Builders WebFOCUS Business Intelligence Portal 8.1 . A specially crafted web parameter can cause a command injection. An authentic…
|
CWE-77
Command Injection
|
CVE-2016-9044
|
2024-11-21 12:00 |
2018-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257349
|
5.5 |
MEDIUM
Local
|
joyent
|
smartos
|
An exploitable denial of service exists in the the Joyent SmartOS OS 20161110T013148Z Hyprlofs file system. The vulnerability is present in the Ioctl system call with the command HYPRLOFSADDENTRIES w…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2016-9040
|
2024-11-21 12:00 |
2018-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257350
|
9.8 |
CRITICAL
Network
|
mozilla
|
firefox
|
Memory safety bugs were reported in Firefox 50.0.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitra…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-9080
|
2024-11-21 12:00 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|