|
268691
|
6.5 |
MEDIUM
Network
|
uclouvain
|
openjpeg
|
Division-by-zero vulnerabilities in the functions opj_pi_next_cprl, opj_pi_next_pcrl, and opj_pi_next_rpcl in pi.c in OpenJPEG before 2.2.0 allow remote attackers to cause a denial of service (applic…
|
CWE-369
Divide By Zero
|
CVE-2016-10506
|
2024-11-21 11:44 |
2017-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268692
|
6.5 |
MEDIUM
Network
|
uclouvain
|
openjpeg
|
NULL pointer dereference vulnerabilities in the imagetopnm function in convert.c, sycc444_to_rgb function in color.c, color_esycc_to_rgb function in color.c, and sycc422_to_rgb function in color.c in…
|
CWE-476
NULL Pointer Dereference
|
CVE-2016-10505
|
2024-11-21 11:44 |
2017-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268693
|
6.5 |
MEDIUM
Network
|
uclouvain
|
openjpeg
|
Heap-based buffer overflow vulnerability in the opj_mqc_byteout function in mqc.c in OpenJPEG before 2.2.0 allows remote attackers to cause a denial of service (application crash) via a crafted bmp f…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-10504
|
2024-11-21 11:44 |
2017-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268694
|
4.3 |
MEDIUM
Network
|
ibm
|
sametime
|
IBM Sametime Meeting Server 8.5.2 and 9.0 could allow an authenticated and invited user of Sametime meeting to lower any or all hands in an e-meeting, thus spoofing results of votes in the meeting. I…
|
CWE-20
Improper Input Validation
|
CVE-2016-10503
|
2024-11-21 11:44 |
2017-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268695
|
6.1 |
MEDIUM
Network
|
apostrophecms
|
sanitize-html
|
sanitize-html before 1.4.3 has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2016-1000237
|
2024-11-21 11:43 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268696
|
6.1 |
MEDIUM
Network
|
smartbear redhat
|
swagger-ui openshift jboss_fuse
|
swagger-ui has XSS in key names
|
CWE-79
Cross-site Scripting
|
CVE-2016-1000229
|
2024-11-21 11:43 |
2019-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268697
|
4.4 |
MEDIUM
Network
|
cookie-signature_project debian
|
cookie-signature debian_linux
|
Node-cookie-signature before 1.0.6 is affected by a timing attack due to the type of comparison used.
|
CWE-362
Race Condition
|
CVE-2016-1000236
|
2024-11-21 11:43 |
2019-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268698
|
6.1 |
MEDIUM
Network
|
doxygen
|
doxygen
|
Insufficient sanitization of the query parameter in templates/html/search_opensearch.php could lead to reflected cross-site scripting or iframe injection.
|
CWE-79
Cross-site Scripting
|
CVE-2016-10245
|
2024-11-21 11:43 |
2019-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268699
|
9.8 |
CRITICAL
Network
|
haraka_project
|
haraka
|
Haraka version 2.8.8 and earlier comes with a plugin for processing attachments for zip files. Versions 2.8.8 and earlier can be vulnerable to command injection.
|
CWE-77
Command Injection
|
CVE-2016-1000282
|
2024-11-21 11:43 |
2019-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268700
|
9.8 |
CRITICAL
Network
|
dthdevelopment
|
dt_register
|
Joomla extension DT Register version before 3.1.12 (Joomla 3.x) / 2.8.18 (Joomla 2.5) contains an SQL injection in "/index.php?controller=calendar&format=raw&cat[0]=SQLi&task=events". This attack app…
|
CWE-89
SQL Injection
|
CVE-2016-1000271
|
2024-11-21 11:43 |
2019-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|