|
256861
|
4.7 |
MEDIUM
Network
|
brave
|
browser
|
Brave Browser iOS before 1.2.18 and Brave Browser Android 1.9.56 and earlier suffer from Full Address Bar Spoofing, allowing attackers to trick a victim by displaying a malicious page for legitimate …
|
CWE-79
Cross-site Scripting
|
CVE-2016-9473
|
2024-11-21 12:01 |
2017-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256862
|
5.4 |
MEDIUM
Network
|
revive-adserver
|
revive_adserver
|
Revive Adserver before 3.2.5 and 4.0.0 suffers from Reflected XSS. The Revive Adserver web installer scripts were vulnerable to a reflected XSS attack via the dbHost, dbUser, and possibly other param…
|
CWE-79
Cross-site Scripting
|
CVE-2016-9472
|
2024-11-21 12:01 |
2017-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256863
|
9.0 |
CRITICAL
Network
|
revive-adserver
|
revive_adserver
|
Revive Adserver before 3.2.5 and 4.0.0 suffers from Reflected File Download. `www/delivery/asyncspc.php` was vulnerable to the fairly new Reflected File Download (RFD) web attack vector that enables …
|
CWE-254
7PK - Security Features
|
CVE-2016-9470
|
2024-11-21 12:01 |
2017-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256864
|
5.3 |
MEDIUM
Network
|
owncloud nextcloud
|
owncloud nextcloud_server
|
Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from content spoofing in the dav app. The exception message displayed on the DAV endpoints contained partiall…
|
CWE-284
Improper Access Control
|
CVE-2016-9468
|
2024-11-21 12:01 |
2017-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256865
|
3.1 |
LOW
Network
|
revive-adserver
|
revive_adserver
|
Revive Adserver before 3.2.5 and 4.0.0 suffers from Special Element Injection. Usernames weren't properly sanitised when creating users on a Revive Adserver instance. Especially, control characters w…
|
NVD-CWE-Other
|
CVE-2016-9471
|
2024-11-21 12:01 |
2017-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256866
|
8.2 |
HIGH
Network
|
gitlab
|
gitlab
|
Multiple versions of GitLab expose a dangerous method to any authenticated user that could lead to the deletion of all Issue and MergeRequest objects on a GitLab instance. For GitLab instances with p…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-9469
|
2024-11-21 12:01 |
2017-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256867
|
5.3 |
MEDIUM
Network
|
owncloud nextcloud
|
owncloud nextcloud_server
|
Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from content spoofing in the files app. The location bar in the files app was not verifying the passed parame…
|
CWE-284
Improper Access Control
|
CVE-2016-9467
|
2024-11-21 12:01 |
2017-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256868
|
6.1 |
MEDIUM
Network
|
owncloud nextcloud
|
owncloud nextcloud_server
|
Nextcloud Server before 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from Reflected XSS in the Gallery application. The gallery app was not properly sanitizing exception messages from the N…
|
CWE-79
Cross-site Scripting
|
CVE-2016-9466
|
2024-11-21 12:01 |
2017-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256869
|
5.4 |
MEDIUM
Network
|
owncloud nextcloud
|
owncloud nextcloud_server
|
Nextcloud Server before 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from Stored XSS in CardDAV image export. The CardDAV image export functionality as implemented in Nextcloud/ownCloud all…
|
CWE-79
Cross-site Scripting
|
CVE-2016-9465
|
2024-11-21 12:01 |
2017-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256870
|
4.3 |
MEDIUM
Network
|
nextcloud
|
nextcloud_server
|
Nextcloud Server before 9.0.54 and 10.0.0 suffers from an improper authorization check on removing shares. The Sharing Backend as implemented in Nextcloud does differentiate between shares to users a…
|
CWE-285
Improper Authorization
|
CVE-2016-9464
|
2024-11-21 12:01 |
2017-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|