|
264481
|
3.3 |
LOW
Local
|
huawei
|
p9_firmware
|
ION memory management module in Huawei P9 phones with software EVA-AL10C00B192 and earlier versions, EVA-DL10C00B192 and earlier versions, EVA-TL10C00B192 and earlier versions, EVA-CL10C00B192 and ea…
|
CWE-200
Information Exposure
|
CVE-2016-8757
|
2024-11-21 12:00 |
2017-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264482
|
5.5 |
MEDIUM
Local
|
huawei
|
mate_8_firmware
|
ION memory management module in Huawei Mate 8 phones with software NXT-AL10C00B197 and earlier versions, NXT-DL10C00B197 and earlier versions, NXT-TL10C00B197 and earlier versions, NXT-CL10C00B197 an…
|
CWE-20
Improper Input Validation
|
CVE-2016-8756
|
2024-11-21 12:00 |
2017-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264483
|
5.4 |
MEDIUM
Network
|
ibm
|
kenexa_lms
|
IBM Kenexa LMS on Cloud 13.1, 13.2, 13.2.2, 13.2.3, 13.2.4 and 14.0.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alt…
|
CWE-79
Cross-site Scripting
|
CVE-2016-8935
|
2024-11-21 12:00 |
2017-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264484
|
8.8 |
HIGH
Network
|
ibm
|
sterling_selling_and_fulfillment_foundation
|
IBM Sterling Order Management 9.2 - 9.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the websit…
|
CWE-352
Origin Validation Error
|
CVE-2016-8917
|
2024-11-21 12:00 |
2017-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264485
|
5.9 |
MEDIUM
Network
|
trendmicro
|
mobile_security
|
There is Missing SSL Certificate Validation in the Trend Micro Enterprise Mobile Security Android Application before 9.7.1193, aka VRTS-398.
|
CWE-295
Improper Certificate Validation
|
CVE-2016-9319
|
2024-11-21 12:00 |
2017-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264486
|
5.5 |
MEDIUM
Local
|
jasper_project fedoraproject
|
jasper fedora
|
The bmp_getdata function in libjasper/bmp/bmp_dec.c in JasPer 1.900.5 allows remote attackers to cause a denial of service (NULL pointer dereference) by calling the imginfo command with a crafted BMP…
|
CWE-476
NULL Pointer Dereference
|
CVE-2016-8884
|
2024-11-21 12:00 |
2017-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264487
|
5.4 |
MEDIUM
Network
|
revive-adserver
|
revive_adserver
|
Revive Adserver before 3.2.3 suffers from Persistent XSS. A vector for persistent XSS attacks via the Revive Adserver user interface exists, requiring a trusted (non-admin) account. The website name …
|
CWE-79
Cross-site Scripting
|
CVE-2016-9130
|
2024-11-21 12:00 |
2017-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264488
|
5.3 |
MEDIUM
Network
|
revive-adserver
|
revive_adserver
|
Revive Adserver before 3.2.3 suffers from Information Exposure Through Discrepancy. It is possible to check whether or not an email address was associated to one or more user accounts on a target Rev…
|
CWE-200
Information Exposure
|
CVE-2016-9129
|
2024-11-21 12:00 |
2017-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264489
|
5.4 |
MEDIUM
Network
|
revive-adserver
|
revive_adserver
|
Revive Adserver before 3.2.3 suffers from reflected XSS. The affiliate-preview.php script in www/admin is vulnerable to a reflected XSS attack. This vulnerability could be used by an attacker to stea…
|
CWE-79
Cross-site Scripting
|
CVE-2016-9128
|
2024-11-21 12:00 |
2017-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264490
|
8.8 |
HIGH
Network
|
revive-adserver
|
revive_adserver
|
Revive Adserver before 3.2.3 suffers from Cross-Site Request Forgery (CSRF). The password recovery form in Revive Adserver is vulnerable to CSRF attacks. This vulnerability could be exploited to send…
|
CWE-352
Origin Validation Error
|
CVE-2016-9127
|
2024-11-21 12:00 |
2017-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|