|
266211
|
9.8 |
CRITICAL
Network
|
python
|
pillow
|
Integer overflow in the ImagingResampleHorizontal function in libImaging/Resample.c in Pillow before 3.1.1 allows remote attackers to have unspecified impact via negative values of the new size, whic…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-4009
|
2024-11-21 11:51 |
2016-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266212
|
8.8 |
HIGH
Network
|
opensuse debian optipng_project canonical
|
leap opensuse debian_linux optipng ubuntu_linux
|
Off-by-one error in the bmp_rle4_fread function in pngxrbmp.c in OptiPNG before 0.7.6 allows remote attackers to cause a denial of service (out-of-bounds read or write access and crash) or possibly e…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-3982
|
2024-11-21 11:51 |
2016-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266213
|
7.8 |
HIGH
Local
|
optipng_project canonical debian
|
optipng ubuntu_linux debian_linux
|
Heap-based buffer overflow in the bmp_read_rows function in pngxrbmp.c in OptiPNG before 0.7.6 allows remote attackers to cause a denial of service (out-of-bounds read or write access and crash) or p…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-3981
|
2024-11-21 11:51 |
2016-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266214
|
9.8 |
CRITICAL
Network
|
opensuse
|
leap opensuse
|
Multiple unspecified vulnerabilities in the obs-service-extract_file package before 0.3-5.1 in openSUSE Leap 42.1 and before 0.3-3.1 in openSUSE 13.2 allow attackers to execute arbitrary commands via…
|
NVD-CWE-noinfo
|
CVE-2016-4007
|
2024-11-21 11:51 |
2016-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266215
|
4.9 |
MEDIUM
Network
|
dell
|
openmanage_server_administrator
|
Directory traversal vulnerability in Dell OpenManage Server Administrator (OMSA) 8.2 allows remote authenticated administrators to read arbitrary files via a ..\ (dot dot backslash) in the file param…
|
CWE-22
Path Traversal
|
CVE-2016-4004
|
2024-11-21 11:51 |
2016-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266216
|
6.1 |
MEDIUM
Network
|
apache
|
struts
|
Cross-site scripting (XSS) vulnerability in the URLDecoder function in JRE before 1.8, as used in Apache Struts 2.x before 2.3.28, when using a single byte page encoding, allows remote attackers to i…
|
CWE-79
Cross-site Scripting
|
CVE-2016-4003
|
2024-11-21 11:51 |
2016-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266217
|
9.8 |
CRITICAL
Network
|
trendmicro
|
password_manager
|
The HTTP server in Trend Micro Password Manager allows remote web servers to execute arbitrary commands via the url parameter to (1) api/openUrlInDefaultBrowser or (2) api/showSB.
|
CWE-284
Improper Access Control
|
CVE-2016-3987
|
2024-11-21 11:51 |
2016-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266218
|
7.8 |
HIGH
Local
|
avast
|
avast
|
Avast allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via a crafted PE file, related to authenticode parsing.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-3986
|
2024-11-21 11:51 |
2016-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266219
|
6.5 |
MEDIUM
Network
|
pulsesecure
|
pulse_connect_secure
|
The Terminal Services Remote Desktop Protocol (RDP) client session restrictions feature in Pulse Connect Secure (aka PCS) 8.1R7 and 8.2R1 allow remote authenticated users to bypass intended access re…
|
CWE-284
Improper Access Control
|
CVE-2016-3985
|
2024-11-21 11:51 |
2016-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266220
|
5.1 |
MEDIUM
Local
|
mcafee
|
data_loss_prevention_endpoint agent virusscan_enterprise host_intrusion_prevention active_response data_exchange_layer endpoint_security
|
The McAfee VirusScan Console (mcconsol.exe) in McAfee Active Response (MAR) before 1.1.0.161, Agent (MA) 5.x before 5.0.2 Hotfix 1110392 (5.0.2.333), Data Exchange Layer 2.x (DXL) before 2.0.1.140.1,…
|
CWE-284
Improper Access Control
|
CVE-2016-3984
|
2024-11-21 11:51 |
2016-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|