|
267671
|
10.0 |
CRITICAL
Network
|
ewww
|
image_optimizer
|
EWWW Image Optimizer before 2.8.5 allows remote command execution because it relies on a protection mechanism involving boolval, which is unavailable before PHP 5.5.
|
NVD-CWE-noinfo
|
CVE-2016-20010
|
2024-11-21 11:47 |
2021-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267672
|
9.8 |
CRITICAL
Network
|
windriver siemens
|
vxworks sgt-100_firmware sgt-200_firmware sgt-300_firmware sgt-400_firmware sgt-a20_firmware sgt-a35_firmware sgt-a65_firmware
|
A DNS client stack-based buffer overflow in ipdnsc_decode_name() affects Wind River VxWorks 6.5 through 7. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
|
CWE-787
Out-of-bounds Write
|
CVE-2016-20009
|
2024-11-21 11:47 |
2021-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267673
|
9.8 |
CRITICAL
Network
|
rest\/json_project
|
rest\/json
|
The REST/JSON project 7.x-1.x for Drupal allows user registration bypass, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.
|
CWE-863
Incorrect Authorization
|
CVE-2016-20005
|
2024-11-21 11:47 |
2021-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267674
|
9.8 |
CRITICAL
Network
|
rest\/json_project
|
rest\/json
|
The REST/JSON project 7.x-1.x for Drupal allows field access bypass, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.
|
CWE-863
Incorrect Authorization
|
CVE-2016-20004
|
2024-11-21 11:47 |
2021-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267675
|
7.5 |
HIGH
Network
|
rest\/json_project
|
rest\/json
|
The REST/JSON project 7.x-1.x for Drupal allows user enumeration, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.
|
NVD-CWE-Other
|
CVE-2016-20003
|
2024-11-21 11:47 |
2021-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267676
|
9.8 |
CRITICAL
Network
|
rest\/json_project
|
rest\/json
|
The REST/JSON project 7.x-1.x for Drupal allows comment access bypass, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.
|
CWE-863
Incorrect Authorization
|
CVE-2016-20002
|
2024-11-21 11:47 |
2021-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267677
|
9.8 |
CRITICAL
Network
|
rest\/json_project
|
rest\/json
|
The REST/JSON project 7.x-1.x for Drupal allows node access bypass, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.
|
CWE-863
Incorrect Authorization
|
CVE-2016-20001
|
2024-11-21 11:47 |
2021-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267678
|
7.5 |
HIGH
Network
|
rest\/json_project
|
rest\/json
|
The REST/JSON project 7.x-1.x for Drupal allows session enumeration, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.
|
NVD-CWE-Other
|
CVE-2016-20008
|
2024-11-21 11:47 |
2021-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267679
|
7.5 |
HIGH
Network
|
rest\/json_project
|
rest\/json
|
The REST/JSON project 7.x-1.x for Drupal allows session name guessing, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.
|
CWE-613
Insufficient Session Expiration
|
CVE-2016-20007
|
2024-11-21 11:47 |
2021-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267680
|
7.5 |
HIGH
Network
|
rest\/json_project
|
rest\/json
|
The REST/JSON project 7.x-1.x for Drupal allows blockage of user logins, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.
|
NVD-CWE-noinfo
|
CVE-2016-20006
|
2024-11-21 11:47 |
2021-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|