|
267261
|
8.8 |
HIGH
Network
|
oracle novell opensuse mozilla
|
linux suse_package_hub_for_suse_linux_enterprise leap opensuse firefox thunderbird
|
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allow remote attackers to cause a denial of service (memory corruption and a…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-1952
|
2024-11-21 11:47 |
2016-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267262
|
8.8 |
HIGH
Network
|
mozilla oracle apple opensuse
|
network_security_services firefox linux vm_server watchos iphone_os mac_os_x tvos glassfish_server iplanet_web_proxy_server iplanet_web_server opensuse
|
Heap-based buffer overflow in Mozilla Network Security Services (NSS) before 3.19.2.3 and 3.20.x and 3.21.x before 3.21.1, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, all…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-1950
|
2024-11-21 11:47 |
2016-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267263
|
6.8 |
MEDIUM
Network
|
isc
|
bind
|
resolver.c in named in ISC BIND 9.10.x before 9.10.3-P4, when DNS cookies are enabled, allows remote attackers to cause a denial of service (INSIST assertion failure and daemon exit) via a malformed …
|
CWE-20
Improper Input Validation
|
CVE-2016-2088
|
2024-11-21 11:47 |
2016-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267264
|
6.5 |
MEDIUM
Network
|
gnu debian
|
cpio debian_linux
|
The cpio_safer_name_suffix function in util.c in cpio 2.11 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted cpio file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-2037
|
2024-11-21 11:47 |
2016-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267265
|
5.4 |
MEDIUM
Network
|
phpmyadmin fedoraproject
|
phpmyadmin fedora
|
Cross-site scripting (XSS) vulnerability in the SQL editor in phpMyAdmin 4.5.x before 4.5.4 allows remote authenticated users to inject arbitrary web script or HTML via a SQL query that triggers JSON…
|
CWE-79
Cross-site Scripting
|
CVE-2016-2045
|
2024-11-21 11:47 |
2016-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267266
|
5.3 |
MEDIUM
Network
|
fedoraproject phpmyadmin
|
fedora phpmyadmin
|
libraries/sql-parser/autoload.php in the SQL parser in phpMyAdmin 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an e…
|
CWE-200
Information Exposure
|
CVE-2016-2044
|
2024-11-21 11:47 |
2016-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267267
|
5.4 |
MEDIUM
Network
|
fedoraproject opensuse phpmyadmin
|
fedora leap opensuse phpmyadmin
|
Cross-site scripting (XSS) vulnerability in the goToFinish1NF function in js/normalization.js in phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote authenticated users to inject ar…
|
CWE-79
Cross-site Scripting
|
CVE-2016-2043
|
2024-11-21 11:47 |
2016-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267268
|
5.3 |
MEDIUM
Network
|
opensuse fedoraproject phpmyadmin
|
leap opensuse fedora phpmyadmin
|
phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request to (1) libraries/phpseclib/Crypt/AES.php or (2) libraries/phpsecl…
|
CWE-200
Information Exposure
|
CVE-2016-2042
|
2024-11-21 11:47 |
2016-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267269
|
7.5 |
HIGH
Network
|
fedoraproject phpmyadmin opensuse
|
fedora phpmyadmin leap opensuse
|
libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not use a constant-time algorithm for comparing CSRF tokens, which makes it easier fo…
|
CWE-254
7PK - Security Features
|
CVE-2016-2041
|
2024-11-21 11:47 |
2016-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267270
|
5.4 |
MEDIUM
Network
|
fedoraproject opensuse phpmyadmin
|
fedora leap opensuse phpmyadmin
|
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 allow remote authenticated users to inject arbitrary web script…
|
CWE-79
Cross-site Scripting
|
CVE-2016-2040
|
2024-11-21 11:47 |
2016-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|