|
265811
|
9.8 |
CRITICAL
Network
|
php
|
pecl_http
|
Buffer overflow in the HTTP URL parsing functions in pecl_http before 3.0.1 might allow remote attackers to execute arbitrary code via non-printable characters in a URL.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-5873
|
2024-11-21 11:55 |
2017-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265812
|
7.8 |
HIGH
Local
|
netbsd
|
netbsd
|
mail.local in NetBSD versions 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows local users to change ownership of or append data to arbitrary files on the target system via a symlink attack on th…
|
CWE-59
Link Following
|
CVE-2016-6253
|
2024-11-21 11:55 |
2017-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265813
|
6.1 |
MEDIUM
Network
|
atlassian
|
confluence
|
Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.10.6 allows remote attackers to inject arbitrary web script or HTML via the newFileName parameter to pages/doeditattachment.a…
|
CWE-79
Cross-site Scripting
|
CVE-2016-6283
|
2024-11-21 11:55 |
2017-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265814
|
7.5 |
HIGH
Network
|
bzrtp_project
|
bzrtp
|
The Bzrtp library (aka libbzrtp) 1.0.x before 1.0.4 allows man-in-the-middle attackers to conduct spoofing attacks by leveraging a missing HVI check on DHPart2 packet reception.
|
CWE-254
7PK - Security Features
|
CVE-2016-6271
|
2024-11-21 11:55 |
2017-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265815
|
7.5 |
HIGH
Network
|
call-cc
|
http-client
|
The "http-client" egg always used a HTTP_PROXY environment variable to determine whether HTTP traffic should be routed via a proxy, even when running as a CGI process. Under several web servers this …
|
CWE-19
Data Processing Errors
|
CVE-2016-6287
|
2024-11-21 11:55 |
2017-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265816
|
7.5 |
HIGH
Network
|
call-cc
|
http-client
|
The "spiffy-cgi-handlers" egg would convert a nonexistent "Proxy" header to the HTTP_PROXY environment variable, which would allow attackers to direct CGI programs which use this environment variable…
|
CWE-19
Data Processing Errors
|
CVE-2016-6286
|
2024-11-21 11:55 |
2017-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265817
|
4.7 |
MEDIUM
Local
|
linux
|
linux_kernel
|
fs/namespace.c in the Linux kernel before 4.9 does not restrict how many mounts may exist in a mount namespace, which allows local users to cause a denial of service (memory consumption and deadlock)…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2016-6213
|
2024-11-21 11:55 |
2016-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265818
|
8.8 |
HIGH
Network
|
python-openxml_project
|
python-docx
|
python-docx before 0.8.6 allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted document.
|
CWE-611
XXE
|
CVE-2016-5851
|
2024-11-21 11:55 |
2016-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265819
|
5.3 |
MEDIUM
Network
|
gnupg debian canonical
|
libgcrypt debian_linux ubuntu_linux gnupg
|
The mixing functions in the random number generator in Libgcrypt before 1.5.6, 1.6.x before 1.6.6, and 1.7.x before 1.7.3 and GnuPG before 1.4.21 make it easier for attackers to obtain the values of …
|
CWE-200
Information Exposure
|
CVE-2016-6313
|
2024-11-21 11:55 |
2016-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265820
|
7.5 |
HIGH
Network
|
imagemagick oracle
|
imagemagick solaris
|
MagickCore/property.c in ImageMagick before 7.0.2-1 allows remote attackers to obtain sensitive memory information via vectors involving the q variable, which triggers an out-of-bounds read.
|
CWE-125
Out-of-bounds Read
|
CVE-2016-5842
|
2024-11-21 11:55 |
2016-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|