|
266161
|
6.1 |
MEDIUM
Network
|
appleple
|
a-blog_cms
|
Cross-site scripting (XSS) vulnerability in the standard template of the comment functionality in appleple a-blog cms 2.6.0.1 and earlier allows remote attackers to inject arbitrary web script or HTM…
|
CWE-79
Cross-site Scripting
|
CVE-2016-1179
|
2024-11-21 11:45 |
2017-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266162
|
6.5 |
MEDIUM
Network
|
appleple
|
a-blog_cms
|
The session management of the comment functionality in appleple a-blog cms 2.6.0.1 and earlier allows remote attackers to obtain or modify sensitive data via unspecified vectors.
|
CWE-284
Improper Access Control
|
CVE-2016-1178
|
2024-11-21 11:45 |
2017-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266163
|
9.8 |
CRITICAL
Network
|
adobe
|
acrobat acrobat_dc acrobat_reader_dc reader
|
Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous before 15.020.20039 on…
|
CWE-416
Use After Free
|
CVE-2016-1091
|
2024-11-21 11:45 |
2016-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266164
|
9.8 |
CRITICAL
Network
|
adobe
|
acrobat acrobat_dc acrobat_reader_dc reader
|
Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous before 15.020.20039 on…
|
CWE-416
Use After Free
|
CVE-2016-1089
|
2024-11-21 11:45 |
2016-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266165
|
8.2 |
HIGH
Network
|
apache
|
struts
|
ActionServlet.java in Apache Struts 1 1.x through 1.3.10 does not properly restrict the Validator configuration, which allows remote attackers to conduct cross-site scripting (XSS) attacks or cause a…
|
CWE-20
Improper Input Validation
|
CVE-2016-1182
|
2024-11-21 11:45 |
2016-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266166
|
8.1 |
HIGH
Network
|
oracle apache
|
banking_platform portal struts
|
ActionServlet.java in Apache Struts 1 1.x through 1.3.10 mishandles multithreaded access to an ActionForm instance, which allows remote attackers to execute arbitrary code or cause a denial of servic…
|
NVD-CWE-noinfo
|
CVE-2016-1181
|
2024-11-21 11:45 |
2016-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266167
|
8.8 |
HIGH
Network
|
ntt-west ntt-east
|
pr-400mi_firmware pr-400mi rt-400mi_firmware rv-440mi_firmware
|
Cross-site request forgery (CSRF) vulnerability on NTT EAST Hikari Denwa routers with firmware PR-400MI, RT-400MI, and RV-440MI 07.00.1006 and earlier and NTT WEST Hikari Denwa routers with firmware …
|
CWE-352
Origin Validation Error
|
CVE-2016-1228
|
2024-11-21 11:45 |
2016-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266168
|
7.2 |
HIGH
Network
|
ntt-east ntt-west
|
rt-400mi_firmware pr-400mi_firmware rv-440mi_firmware
|
NTT EAST Hikari Denwa routers with firmware PR-400MI, RT-400MI, and RV-440MI 07.00.1006 and earlier and NTT WEST Hikari Denwa routers with firmware PR-400MI, RT-400MI, and RV-440MI 07.00.1005 and ear…
|
NVD-CWE-noinfo
|
CVE-2016-1227
|
2024-11-21 11:45 |
2016-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266169
|
7.5 |
HIGH
Network
|
cybozu
|
garoon
|
Cybozu Garoon 3.7 through 4.2 allows remote attackers to obtain sensitive email-reading information via unspecified vectors.
|
CWE-200
Information Exposure
|
CVE-2016-1193
|
2024-11-21 11:45 |
2016-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266170
|
6.5 |
MEDIUM
Network
|
cybozu
|
garoon
|
Cybozu Garoon 3.1 through 4.2 allows remote authenticated users to bypass intended restrictions on MultiReport reading via unspecified vectors.
|
CWE-284
Improper Access Control
|
CVE-2016-1190
|
2024-11-21 11:45 |
2016-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|