|
257041
|
4.3 |
MEDIUM
Network
|
owncloud nextcloud
|
owncloud nextcloud_server
|
Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are not properly verifying edit check permissions on WebDAV copy actions. The WebDAV endpoint was not properly checking the permission on…
|
CWE-284
Improper Access Control
|
CVE-2016-9461
|
2024-11-21 12:01 |
2017-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257042
|
5.3 |
MEDIUM
Network
|
nextcloud owncloud
|
nextcloud owncloud
|
Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are vulnerable to a content-spoofing attack in the files app. The location bar in the files app was not verifying the passed parameters. …
|
CWE-284
Improper Access Control
|
CVE-2016-9460
|
2024-11-21 12:01 |
2017-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257043
|
6.1 |
MEDIUM
Network
|
owncloud nextcloud
|
owncloud nextcloud_server
|
Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are vulnerable to a log pollution vulnerability potentially leading to a local XSS. The download log functionality in the admin screen is…
|
CWE-79
Cross-site Scripting
|
CVE-2016-9459
|
2024-11-21 12:01 |
2017-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257044
|
5.4 |
MEDIUM
Network
|
revive-adserver
|
revive_adserver
|
Revive Adserver before 3.2.3 suffers from Reflected XSS. `www/admin/stats.php` is vulnerable to reflected XSS attacks via multiple parameters that are not properly sanitised or escaped when displayed…
|
CWE-79
Cross-site Scripting
|
CVE-2016-9457
|
2024-11-21 12:01 |
2017-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257045
|
8.8 |
HIGH
Network
|
revive-adserver
|
revive_adserver
|
Revive Adserver before 3.2.3 suffers from Cross-Site Request Forgery (CSRF). The Revive Adserver team conducted a security audit of the admin interface scripts in order to identify and fix other pote…
|
CWE-352
Origin Validation Error
|
CVE-2016-9456
|
2024-11-21 12:01 |
2017-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257046
|
8.8 |
HIGH
Network
|
revive-adserver
|
revive_adserver
|
Revive Adserver before 3.2.3 suffers from Cross-Site Request Forgery (CSRF). A number of scripts in Revive Adserver's user interface are vulnerable to CSRF attacks: `www/admin/banner-acl.php`, `www/a…
|
CWE-352
Origin Validation Error
|
CVE-2016-9455
|
2024-11-21 12:01 |
2017-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257047
|
5.4 |
MEDIUM
Network
|
revive-adserver
|
revive_adserver
|
Revive Adserver before 3.2.3 suffers from Persistent XSS. A vector for persistent XSS attacks via the Revive Adserver user interface exists, requiring a trusted (non-admin) account. The banner image …
|
CWE-79
Cross-site Scripting
|
CVE-2016-9454
|
2024-11-21 12:01 |
2017-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257048
|
5.4 |
MEDIUM
Network
|
ibm
|
tririga_application_platform
|
IBM TRIRIGA 3.3, 3.4, and 3.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentia…
|
CWE-79
Cross-site Scripting
|
CVE-2016-9737
|
2024-11-21 12:01 |
2017-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257049
|
5.5 |
MEDIUM
Local
|
jasper_project
|
jasper
|
Integer overflow in jas_image.c in JasPer before 1.900.25 allows remote attackers to cause a denial of service (application crash) via a crafted file.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2016-9557
|
2024-11-21 12:01 |
2017-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257050
|
5.5 |
MEDIUM
Local
|
imagemagick opensuse_project debian
|
imagemagick leap debian_linux
|
The IsPixelGray function in MagickCore/pixel-accessor.h in ImageMagick 7.0.3-8 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted image file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-9556
|
2024-11-21 12:01 |
2017-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|