|
265341
|
6.1 |
MEDIUM
Network
|
phpmyadmin
|
phpmyadmin
|
XSS issues were discovered in phpMyAdmin. This affects Zoom search (specially crafted column content can be used to trigger an XSS attack); GIS editor (certain fields in the graphical GIS editor are …
|
CWE-79
Cross-site Scripting
|
CVE-2016-6607
|
2024-11-21 11:56 |
2016-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265342
|
8.1 |
HIGH
Network
|
phpmyadmin
|
phpmyadmin
|
An issue was discovered in cookie encryption in phpMyAdmin. The decryption of the username/password is vulnerable to a padding oracle attack. This can allow an attacker who has access to a user's bro…
|
CWE-310 CWE-200
Cryptographic Issues Information Exposure
|
CVE-2016-6606
|
2024-11-21 11:56 |
2016-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265343
|
6.0 |
MEDIUM
Local
|
qemu debian
|
qemu debian_linux
|
The vmxnet3_complete_packet function in hw/net/vmxnet3.c in QEMU (aka Quick Emulator) allows local guest OS administrators to obtain sensitive host memory information by leveraging failure to initial…
|
CWE-665
Improper Initialization
|
CVE-2016-6836
|
2024-11-21 11:56 |
2016-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265344
|
6.0 |
MEDIUM
Local
|
qemu redhat debian
|
qemu virtualization debian_linux
|
The vmxnet_tx_pkt_parse_headers function in hw/net/vmxnet_tx_pkt.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (buffer over-read) by leveraging fail…
|
NVD-CWE-Other
|
CVE-2016-6835
|
2024-11-21 11:56 |
2016-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265345
|
4.4 |
MEDIUM
Local
|
qemu debian
|
qemu debian_linux
|
The net_tx_pkt_do_sw_fragmentation function in hw/net/net_tx_pkt.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash…
|
CWE-120
Classic Buffer Overflow
|
CVE-2016-6834
|
2024-11-21 11:56 |
2016-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265346
|
4.4 |
MEDIUM
Local
|
qemu debian
|
qemu debian_linux
|
Use-after-free vulnerability in the vmxnet3_io_bar0_write function in hw/net/vmxnet3.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (QEMU instance cr…
|
CWE-416
Use After Free
|
CVE-2016-6833
|
2024-11-21 11:56 |
2016-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265347
|
4.4 |
MEDIUM
Local
|
qemu
|
qemu
|
The virtqueue_map_desc function in hw/virtio/virtio.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via a zero …
|
CWE-120
Classic Buffer Overflow
|
CVE-2016-6490
|
2024-11-21 11:56 |
2016-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265348
|
9.8 |
CRITICAL
Network
|
jfrog
|
artifactory
|
JFrog Artifactory before 4.11 allows remote attackers to execute arbitrary code via an LDAP attribute with a crafted serialized Java object, aka LDAP entry poisoning.
|
CWE-20
Improper Input Validation
|
CVE-2016-6501
|
2024-11-21 11:56 |
2016-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265349
|
9.8 |
CRITICAL
Network
|
atlassian
|
crowd
|
The LDAP directory connector in Atlassian Crowd before 2.8.8 and 2.9.x before 2.9.5 allows remote attackers to execute arbitrary code via an LDAP attribute with a crafted serialized Java object, aka …
|
CWE-20
Improper Input Validation
|
CVE-2016-6496
|
2024-11-21 11:56 |
2016-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265350
|
9.8 |
CRITICAL
Network
|
barclamp-trove_project crowbar-openstack_project
|
barclamp-trove crowbar-openstack
|
The trove service user in (1) Openstack deployment (aka crowbar-openstack) and (2) Trove Barclamp (aka barclamp-trove and crowbar-barclamp-trove) in the Crowbar Framework has a default password, whic…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2016-6829
|
2024-11-21 11:56 |
2016-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|