|
266111
|
8.1 |
HIGH
Network
|
qualcomm
|
mdm9206_firmware mdm9625_firmware mdm9635m_firmware mdm9640_firmware mdm9645_firmware msm8909w_firmware sd_210_firmware sd_212_firmware sd_205_firmware sd_400_firmware s…
|
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9206, MDM9625, MDM9635M, MDM9640, MDM9645, MSM8909W, SD 210/S…
|
CWE-362
Race Condition
|
CVE-2016-10435
|
2024-11-21 11:44 |
2018-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266112
|
7.5 |
HIGH
Network
|
qualcomm
|
sd_820_firmware sd_820a_firmware
|
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile SD 820 and SD 820A, the input to RPMB write response function is a buffer from HLO…
|
CWE-287
Improper Authentication
|
CVE-2016-10434
|
2024-11-21 11:44 |
2018-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266113
|
7.5 |
HIGH
Network
|
brave
|
brave_browser
|
Brave Browser before 0.13.0 allows a tab to close itself even if the tab was not opened by a script, resulting in denial of service.
|
CWE-20
Improper Input Validation
|
CVE-2016-10718
|
2024-11-21 11:44 |
2018-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266114
|
7.8 |
HIGH
Local
|
malwarebytes
|
malwarebytes_anti-malware
|
A vulnerability in the encryption and permission implementation of Malwarebytes Anti-Malware consumer version 2.2.1 and prior (fixed in 3.0.4) allows an attacker to take control of the whitelisting f…
|
CWE-254
7PK - Security Features
|
CVE-2016-10717
|
2024-11-21 11:44 |
2018-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266115
|
5.4 |
MEDIUM
Network
|
mail.ru
|
calendar
|
The Mail.ru Calendar plugin before 2.5.0.61 for Atlassian Jira has XSS via the Name field in a Create Calender action, related to a MailRuCalendar.jspa#period/month URI.
|
CWE-79
Cross-site Scripting
|
CVE-2016-10716
|
2024-11-21 11:44 |
2018-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266116
|
5.4 |
MEDIUM
Network
|
artezio
|
kanban_board
|
The Artezio Kanban Board plugin 1.4 revision 1914 for Atlassian Jira has XSS via the Board Name in a Create New Board action, related to an artezioboard/mainPage.jspa?kanbanId=7#/kanban-view URI.
|
CWE-79
Cross-site Scripting
|
CVE-2016-10715
|
2024-11-21 11:44 |
2018-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266117
|
9.8 |
CRITICAL
Network
|
zsh canonical
|
zsh ubuntu_linux
|
In zsh before 5.3, an off-by-one error resulted in undersized buffers that were intended to support PATH_MAX characters.
|
CWE-189
Numeric Errors
|
CVE-2016-10714
|
2024-11-21 11:44 |
2018-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266118
|
5.5 |
MEDIUM
Local
|
gnu
|
patch
|
An issue was discovered in GNU patch before 2.7.6. Out-of-bounds access within pch_write_line() in pch.c can possibly lead to DoS via a crafted input file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-10713
|
2024-11-21 11:44 |
2018-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266119
|
7.5 |
HIGH
Network
|
php canonical
|
php ubuntu_linux
|
In PHP before 5.5.32, 5.6.x before 5.6.18, and 7.x before 7.0.3, all of the return values of stream_get_meta_data can be controlled if the input can be controlled (e.g., during file uploads). For exa…
|
CWE-20
Improper Input Validation
|
CVE-2016-10712
|
2024-11-21 11:44 |
2018-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266120
|
9.8 |
CRITICAL
Network
|
debian apsis
|
debian_linux pound
|
Apsis Pound before 2.8a allows request smuggling via crafted headers, a different vulnerability than CVE-2005-3751.
|
CWE-444
HTTP Request Smuggling
|
CVE-2016-10711
|
2024-11-21 11:44 |
2018-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|