|
264521
|
9.8 |
CRITICAL
Network
|
jqueryform
|
php_formmail_generator
|
The PHP form code generated by PHP FormMail Generator deserializes untrusted input as part of the phpfmg_filman_download() function. A remote unauthenticated attacker may be able to use this vulnerab…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2016-9483
|
2024-11-21 12:01 |
2018-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264522
|
9.8 |
CRITICAL
Network
|
jqueryform
|
php_formmail_generator
|
Code generated by PHP FormMail Generator may allow a remote unauthenticated user to bypass authentication in the to access the administrator panel by navigating directly to /admin.php?mod=admin&func=…
|
CWE-287
Improper Authentication
|
CVE-2016-9482
|
2024-11-21 12:01 |
2018-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264523
|
9.8 |
CRITICAL
Network
|
zohocorp
|
manageengine_applications_manager
|
ManageEngine Applications Manager 12 and 13 before build 13200, allows unserialization of unsafe Java objects. The vulnerability can be exploited by remote user without authentication and it allows t…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2016-9498
|
2024-11-21 12:01 |
2018-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264524
|
6.1 |
MEDIUM
Network
|
jqueryform
|
php_formmail_generator
|
The code generated by PHP FormMail Generator prior to 17 December 2016 is vulnerable to stored cross-site scripting. In the generated form.lib.php file, upload file types are checked against a hard-c…
|
CWE-79
Cross-site Scripting
|
CVE-2016-9493
|
2024-11-21 12:01 |
2018-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264525
|
9.8 |
CRITICAL
Network
|
jqueryform
|
php_formmail_generator
|
The code generated by PHP FormMail Generator prior to 17 December 2016 is vulnerable to unrestricted upload of dangerous file types. In the generated form.lib.php file, upload file types are checked …
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2016-9492
|
2024-11-21 12:01 |
2018-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264526
|
7.8 |
HIGH
Local
|
forescout
|
secureconnector
|
On Windows endpoints, the SecureConnector agent must run under the local SYSTEM account or another administrator account in order to enable full functionality of the agent. The typical configuration …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-9486
|
2024-11-21 12:01 |
2018-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264527
|
7.8 |
HIGH
Local
|
forescout
|
secureconnector
|
On Windows endpoints, the SecureConnector agent must run under the local SYSTEM account or another administrator account in order to enable full functionality of the agent. The typical configuration …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-9485
|
2024-11-21 12:01 |
2018-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264528
|
4.4 |
MEDIUM
Local
|
linux
|
linux_kernel
|
It was discovered in the Linux kernel before 4.11-rc8 that root can gain direct access to an internal keyring, such as '.dns_resolver' in RHEL-7 or '.builtin_trusted_keys' upstream, by joining it as …
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2016-9604
|
2024-11-21 12:01 |
2018-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264529
|
8.8 |
HIGH
Network
|
redhat debian mozilla
|
enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation debian_linux thunderbird firefox_esr
|
A potentially exploitable crash in "EnumerateSubDocuments" while adding or removing sub-documents. This vulnerability affects Firefox ESR < 45.6 and Thunderbird < 45.6.
|
CWE-284
Improper Access Control
|
CVE-2016-9905
|
2024-11-21 12:01 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264530
|
7.5 |
HIGH
Network
|
redhat debian mozilla
|
enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation debian_linux thunderbird firefox firefox_esr
|
An attacker could use a JavaScript Map/Set timing attack to determine whether an atom is used by another compartment/zone in specific contexts. This could be used to leak information, such as usernam…
|
CWE-200
Information Exposure
|
CVE-2016-9904
|
2024-11-21 12:01 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|