|
269351
|
7.5 |
HIGH
Network
|
sequelizejs
|
sequelize
|
sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server into usable data for NodeJS In Postgres, SQLite, and Microso…
|
CWE-89
SQL Injection
|
CVE-2016-10556
|
2024-11-21 11:44 |
2018-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269352
|
9.8 |
CRITICAL
Network
|
balderdash
|
waterline-sequel
|
waterline-sequel is a module that helps generate SQL statements for Waterline apps Any user input that goes into Waterline's `like`, `contains`, `startsWith`, or `endsWith` will end up in waterline-s…
|
CWE-89
SQL Injection
|
CVE-2016-10551
|
2024-11-21 11:44 |
2018-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269353
|
9.8 |
CRITICAL
Network
|
dwyl
|
hapi-auth-jwt2
|
When attempting to allow authentication mode `try` in hapi, hapi-auth-jwt2 version 5.1.1 introduced an issue whereby people could bypass authentication.
|
CWE-287
Improper Authentication
|
CVE-2016-10525
|
2024-11-21 11:44 |
2018-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269354
|
9.8 |
CRITICAL
Network
|
partclone_project
|
partclone
|
partclone.fat in Partclone before 0.2.88 is prone to a heap-based buffer overflow vulnerability due to insufficient validation of the FAT superblock, related to the mark_reserved_sectors function. An…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-10722
|
2024-11-21 11:44 |
2018-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269355
|
9.8 |
CRITICAL
Network
|
partclone
|
partclone
|
partclone.restore in Partclone 0.2.87 is prone to a heap-based buffer overflow vulnerability due to insufficient validation of the partclone image header. An attacker may be able to execute arbitrary…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-10721
|
2024-11-21 11:44 |
2018-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269356
|
9.8 |
CRITICAL
Network
|
qualcomm
|
mdm9635m_firmware
|
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9635M, made changes to map the scan type value to an index value that is in range.
|
CWE-118
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-10495
|
2024-11-21 11:44 |
2018-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269357
|
9.8 |
CRITICAL
Network
|
qualcomm
|
sd_400_firmware
|
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 400, lack of address argument validation in qsee_get_tz_app_name() may lead to an untrusted pointer deref…
|
CWE-476
NULL Pointer Dereference
|
CVE-2016-10489
|
2024-11-21 11:44 |
2018-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269358
|
7.5 |
HIGH
Network
|
qualcomm
|
sd_410_firmware sd_412_firmware sd_615_firmware sd_616_firmware sd_415_firmware sd_808_firmware sd_810_firmware
|
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 410/12, SD 615/16/SD 415, SD 808, and SD 810, improper input validation while processing SCM Command can …
|
CWE-20
Improper Input Validation
|
CVE-2016-10483
|
2024-11-21 11:44 |
2018-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269359
|
9.8 |
CRITICAL
Network
|
qualcomm
|
sd_617_firmware
|
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 617, incorrect size calculation in QCRIL SCWS processing have Integer overflow which will lead to a buffe…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2016-10478
|
2024-11-21 11:44 |
2018-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269360
|
9.8 |
CRITICAL
Network
|
qualcomm
|
sd_425_firmware sd_430_firmware sd_450_firmware sd_625_firmware sd_650_firmware sd_652_firmware sd_820_firmware sd_820a_firmware
|
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 820, and SD 820A, an unsigned RTIC h…
|
NVD-CWE-noinfo
|
CVE-2016-10471
|
2024-11-21 11:44 |
2018-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|