|
264971
|
6.5 |
MEDIUM
Network
|
libdwarf_project
|
libdwarf
|
The print_exprloc_content function in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file.
|
CWE-125
Out-of-bounds Read
|
CVE-2016-5033
|
2024-11-21 11:53 |
2017-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264972
|
6.5 |
MEDIUM
Network
|
libdwarf_project
|
libdwarf
|
The dwarf_get_xu_hash_entry function in libdwarf before 20160923 allows remote attackers to cause a denial of service (crash) via a crafted file.
|
CWE-125
Out-of-bounds Read
|
CVE-2016-5032
|
2024-11-21 11:53 |
2017-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264973
|
5.5 |
MEDIUM
Local
|
libdwarf_project
|
libdwarf
|
The print_frame_inst_bytes function in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file.
|
CWE-125
Out-of-bounds Read
|
CVE-2016-5031
|
2024-11-21 11:53 |
2017-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264974
|
6.5 |
MEDIUM
Network
|
libdwarf_project
|
libdwarf
|
The _dwarf_calculate_info_section_end_ptr function in libdwarf before 20160923 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.
|
CWE-476
NULL Pointer Dereference
|
CVE-2016-5030
|
2024-11-21 11:53 |
2017-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264975
|
6.5 |
MEDIUM
Network
|
libdwarf_project
|
libdwarf
|
The create_fullest_file_path function in libdwarf before 20160923 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted dwarf file.
|
CWE-476
NULL Pointer Dereference
|
CVE-2016-5029
|
2024-11-21 11:53 |
2017-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264976
|
6.5 |
MEDIUM
Network
|
libdwarf_project
|
libdwarf
|
The print_frame_inst_bytes function in libdwarf before 20160923 allows remote attackers to cause a denial of service (NULL pointer dereference) via an object file with empty bss-like sections.
|
CWE-476
NULL Pointer Dereference
|
CVE-2016-5028
|
2024-11-21 11:53 |
2017-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264977
|
9.8 |
CRITICAL
Network
|
fedoraproject zend
|
fedora zend_framework
|
The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.20 might allow remote attackers to conduct SQL injection attacks by leveraging failure to remove comments from …
|
CWE-89
SQL Injection
|
CVE-2016-4861
|
2024-11-21 11:53 |
2017-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264978
|
9.8 |
CRITICAL
Network
|
froxlor
|
froxlor
|
Froxlor before 0.9.35 uses the PHP rand function for random number generation, which makes it easier for remote attackers to guess the password reset token by predicting a value.
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2016-5100
|
2024-11-21 11:53 |
2017-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264979
|
6.1 |
MEDIUM
Network
|
jenkins
|
build_failure_analyzer
|
Cross-site scripting (XSS) vulnerability in the Build Failure Analyzer plugin before 1.16.0 in Jenkins allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2016-4988
|
2024-11-21 11:53 |
2017-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264980
|
6.5 |
MEDIUM
Network
|
jenkins
|
image_gallery
|
Directory traversal vulnerability in the Image Gallery plugin before 1.4 in Jenkins allows remote attackers to list arbitrary directories and read arbitrary files via unspecified form fields.
|
CWE-22
Path Traversal
|
CVE-2016-4987
|
2024-11-21 11:53 |
2017-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|