|
266141
|
5.4 |
MEDIUM
Network
|
fedoraproject opensuse phpmyadmin
|
fedora leap opensuse phpmyadmin
|
Cross-site scripting (XSS) vulnerability in the goToFinish1NF function in js/normalization.js in phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote authenticated users to inject ar…
|
CWE-79
Cross-site Scripting
|
CVE-2016-2043
|
2024-11-21 11:47 |
2016-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266142
|
5.3 |
MEDIUM
Network
|
opensuse fedoraproject phpmyadmin
|
leap opensuse fedora phpmyadmin
|
phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request to (1) libraries/phpseclib/Crypt/AES.php or (2) libraries/phpsecl…
|
CWE-200
Information Exposure
|
CVE-2016-2042
|
2024-11-21 11:47 |
2016-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266143
|
7.5 |
HIGH
Network
|
fedoraproject phpmyadmin opensuse
|
fedora phpmyadmin leap opensuse
|
libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not use a constant-time algorithm for comparing CSRF tokens, which makes it easier fo…
|
CWE-254
7PK - Security Features
|
CVE-2016-2041
|
2024-11-21 11:47 |
2016-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266144
|
5.4 |
MEDIUM
Network
|
fedoraproject opensuse phpmyadmin
|
fedora leap opensuse phpmyadmin
|
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 allow remote authenticated users to inject arbitrary web script…
|
CWE-79
Cross-site Scripting
|
CVE-2016-2040
|
2024-11-21 11:47 |
2016-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266145
|
5.3 |
MEDIUM
Network
|
opensuse phpmyadmin fedoraproject
|
leap opensuse phpmyadmin fedora
|
libraries/session.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not properly generate CSRF token values, which allows remote attackers to bypass int…
|
CWE-200
Information Exposure
|
CVE-2016-2039
|
2024-11-21 11:47 |
2016-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266146
|
5.3 |
MEDIUM
Network
|
phpmyadmin fedoraproject opensuse
|
phpmyadmin fedora leap opensuse
|
phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error…
|
CWE-200
Information Exposure
|
CVE-2016-2038
|
2024-11-21 11:47 |
2016-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266147
|
7.5 |
HIGH
Network
|
phpmyadmin
|
phpmyadmin
|
The suggestPassword function in js/functions.js in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 relies on the Math.random JavaScript function, which makes it easie…
|
CWE-255 CWE-254
Credentials Management 7PK - Security Features
|
CVE-2016-1927
|
2024-11-21 11:47 |
2016-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266148
|
5.9 |
MEDIUM
Network
|
hp
|
hp-ux_ipfilter
|
HPE IPFilter A.11.31.18.21 on HP-UX, when a certain keep-state configuration is enabled, allows remote attackers to cause a denial of service via unspecified UDP packets.
|
CWE-20
Improper Input Validation
|
CVE-2016-1987
|
2024-11-21 11:47 |
2016-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266149
|
6.1 |
MEDIUM
Network
|
citrix
|
netscaler
|
The Administrative Web Interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 11.x before 11.0 Build 64.34, 10.5 before 10.5 Build 59.13, 10.5.e before Build 59.130…
|
CWE-254
7PK - Security Features
|
CVE-2016-2072
|
2024-11-21 11:47 |
2016-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266150
|
9.8 |
CRITICAL
Network
|
citrix
|
netscaler
|
Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 11.x before 11.0 Build 64.34, 10.5 before 10.5 Build 59.13, and 10.5.e before Build 59.1305.e allows remote attackers to g…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-2071
|
2024-11-21 11:47 |
2016-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|