|
264971
|
4.3 |
MEDIUM
Network
|
mozilla
|
firefox
|
Mozilla Firefox before 48.0 allows remote attackers to spoof the location bar via crafted characters in the media type of a data: URL.
|
CWE-20
Improper Input Validation
|
CVE-2016-5251
|
2024-11-21 11:53 |
2016-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264972
|
4.3 |
MEDIUM
Network
|
mozilla
|
firefox
|
Mozilla Firefox before 48.0, Firefox ESR < 45.4 and Thunderbird < 45.4 allow remote attackers to obtain sensitive information about the previously retrieved page via Resource Timing API calls.
|
CWE-200
Information Exposure
|
CVE-2016-5250
|
2024-11-21 11:53 |
2016-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264973
|
6.1 |
MEDIUM
Network
|
nofollow_links_project
|
nofollow_links
|
Cross-site scripting (XSS) vulnerability in the Nofollow Links plugin before 1.0.11 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2016-4833
|
2024-11-21 11:53 |
2016-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264974
|
9.8 |
CRITICAL
Network
|
atlassian
|
bamboo
|
Atlassian Bamboo before 5.11.4.1 and 5.12.x before 5.12.3.1 does not properly restrict permitted deserialized classes, which allows remote attackers to execute arbitrary code via vectors related to X…
|
CWE-284
Improper Access Control
|
CVE-2016-5229
|
2024-11-21 11:53 |
2016-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264975
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Integer overflow in the kbasep_vinstr_attach_client function in midgard/mali_kbase_vinstr.c in Google Chrome before 52.0.2743.85 allows remote attackers to cause a denial of service (heap-based buffe…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2016-5138
|
2024-11-21 11:53 |
2016-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264976
|
9.8 |
CRITICAL
Network
|
ec-cube
|
discount_coupon
|
SQL injection vulnerability in the Seed Coupon plugin before 1.6 for EC-CUBE allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2016-4837
|
2024-11-21 11:53 |
2016-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264977
|
8.1 |
HIGH
Network
|
vtiger
|
vtiger_crm
|
modules/Users/actions/Save.php in Vtiger CRM 6.4.0 and earlier does not properly restrict user-save actions, which allows remote authenticated users to create or modify user accounts via unspecified …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-4834
|
2024-11-21 11:53 |
2016-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264978
|
4.8 |
MEDIUM
Network
|
apache
|
archiva
|
Cross-site scripting (XSS) vulnerability in Apache Archiva 1.3.9 and earlier allows remote authenticated administrators to inject arbitrary web script or HTML via the connector.sourceRepoId parameter…
|
CWE-79
Cross-site Scripting
|
CVE-2016-5005
|
2024-11-21 11:53 |
2016-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264979
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use-after-free vulnerability in extensions/renderer/user_script_injector.cc in the Extensions subsystem in Google Chrome before 52.0.2743.82 allows remote attackers to cause a denial of service or po…
|
CWE-416
Use After Free
|
CVE-2016-5136
|
2024-11-21 11:53 |
2016-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264980
|
4.3 |
MEDIUM
Network
|
google
|
chrome
|
The CSPSource::schemeMatches function in WebKit/Source/core/frame/csp/CSPSource.cpp in the Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 52.0.2743.82, does no…
|
CWE-200
Information Exposure
|
CVE-2016-5137
|
2024-11-21 11:53 |
2016-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|