|
264971
|
8.1 |
HIGH
Network
|
oracle fedoraproject hp php redhat debian opensuse drupal
|
enterprise_manager_ops_center communications_user_data_repository linux fedora storeever_msl6480_tape_library_firmware system_management_homepage php enterprise_linux_desktop …
|
PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY envi…
|
CWE-601
Open Redirect
|
CVE-2016-5385
|
2024-11-21 11:54 |
2016-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264972
|
8.8 |
HIGH
Network
|
accela
|
civic_platform_citizen_access_portal
|
Accela Civic Platform Citizen Access portal relies on the client to restrict file types for uploads, which allows remote authenticated users to execute arbitrary code via modified _EventArgument and …
|
CWE-284
Improper Access Control
|
CVE-2016-5661
|
2024-11-21 11:54 |
2016-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264973
|
6.1 |
MEDIUM
Network
|
accela
|
civic_platform
|
Cross-site scripting (XSS) vulnerability in AttachmentsList.aspx in Accela Civic Platform Citizen Access portal allows remote attackers to inject arbitrary web script or HTML via the iframeid paramet…
|
CWE-79
Cross-site Scripting
|
CVE-2016-5660
|
2024-11-21 11:54 |
2016-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264974
|
8.8 |
HIGH
Network
|
libbpg_project
|
libbpg
|
The restore_tqb_pixels function in libbpg 0.9.5 through 0.9.7 mishandles the transquant_bypass_enable_flag value, which allows remote attackers to execute arbitrary code or cause a denial of service …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-5637
|
2024-11-21 11:54 |
2016-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264975
|
5.5 |
MEDIUM
Local
|
symantec
|
client_intrusion_detection_system
|
The Client Intrusion Detection System (CIDS) driver before 15.0.6 in Symantec Endpoint Protection (SEP) and before 15.1.2 in Norton Security allows remote attackers to cause a denial of service (memo…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-5308
|
2024-11-21 11:54 |
2016-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264976
|
7.5 |
HIGH
Network
|
opensuse phpmyadmin
|
leap opensuse phpmyadmin
|
The Transformation implementation in phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not use the no-referrer Content Security Policy (CSP) protection mechanism, …
|
CWE-200
Information Exposure
|
CVE-2016-5739
|
2024-11-21 11:54 |
2016-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264977
|
9.8 |
CRITICAL
Network
|
phpmyadmin
|
phpmyadmin
|
phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not properly choose delimiters to prevent use of the preg_replace e (aka eval) modifier, which might allow remote…
|
CWE-94
Code Injection
|
CVE-2016-5734
|
2024-11-21 11:54 |
2016-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264978
|
6.1 |
MEDIUM
Network
|
phpmyadmin opensuse
|
phpmyadmin leap opensuse
|
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 allow remote attackers to inject arbitrary web script or HTML v…
|
CWE-79
Cross-site Scripting
|
CVE-2016-5733
|
2024-11-21 11:54 |
2016-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264979
|
6.1 |
MEDIUM
Network
|
phpmyadmin
|
phpmyadmin
|
Multiple cross-site scripting (XSS) vulnerabilities in the partition-range implementation in templates/table/structure/display_partitions.phtml in the table-structure page in phpMyAdmin 4.6.x before …
|
CWE-79
Cross-site Scripting
|
CVE-2016-5732
|
2024-11-21 11:54 |
2016-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264980
|
6.1 |
MEDIUM
Network
|
phpmyadmin opensuse
|
phpmyadmin leap opensuse
|
Cross-site scripting (XSS) vulnerability in examples/openid.php in phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 allows remote attackers to inject arbitrary web scr…
|
CWE-79
Cross-site Scripting
|
CVE-2016-5731
|
2024-11-21 11:54 |
2016-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|