|
271691
|
6.5 |
MEDIUM
Network
|
uclouvain
|
openjpeg
|
Heap-based buffer overflow vulnerability in the opj_mqc_byteout function in mqc.c in OpenJPEG before 2.2.0 allows remote attackers to cause a denial of service (application crash) via a crafted bmp f…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-10504
|
2024-11-21 11:44 |
2017-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271692
|
4.3 |
MEDIUM
Network
|
ibm
|
sametime
|
IBM Sametime Meeting Server 8.5.2 and 9.0 could allow an authenticated and invited user of Sametime meeting to lower any or all hands in an e-meeting, thus spoofing results of votes in the meeting. I…
|
CWE-20
Improper Input Validation
|
CVE-2016-10503
|
2024-11-21 11:44 |
2017-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271693
|
6.1 |
MEDIUM
Network
|
apostrophecms
|
sanitize-html
|
sanitize-html before 1.4.3 has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2016-1000237
|
2024-11-21 11:43 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271694
|
6.1 |
MEDIUM
Network
|
smartbear redhat
|
swagger-ui openshift jboss_fuse
|
swagger-ui has XSS in key names
|
CWE-79
Cross-site Scripting
|
CVE-2016-1000229
|
2024-11-21 11:43 |
2019-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271695
|
4.4 |
MEDIUM
Network
|
cookie-signature_project debian
|
cookie-signature debian_linux
|
Node-cookie-signature before 1.0.6 is affected by a timing attack due to the type of comparison used.
|
CWE-362
Race Condition
|
CVE-2016-1000236
|
2024-11-21 11:43 |
2019-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271696
|
6.1 |
MEDIUM
Network
|
doxygen
|
doxygen
|
Insufficient sanitization of the query parameter in templates/html/search_opensearch.php could lead to reflected cross-site scripting or iframe injection.
|
CWE-79
Cross-site Scripting
|
CVE-2016-10245
|
2024-11-21 11:43 |
2019-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271697
|
9.8 |
CRITICAL
Network
|
haraka_project
|
haraka
|
Haraka version 2.8.8 and earlier comes with a plugin for processing attachments for zip files. Versions 2.8.8 and earlier can be vulnerable to command injection.
|
CWE-77
Command Injection
|
CVE-2016-1000282
|
2024-11-21 11:43 |
2019-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271698
|
9.8 |
CRITICAL
Network
|
dthdevelopment
|
dt_register
|
Joomla extension DT Register version before 3.1.12 (Joomla 3.x) / 2.8.18 (Joomla 2.5) contains an SQL injection in "/index.php?controller=calendar&format=raw&cat[0]=SQLi&task=events". This attack app…
|
CWE-89
SQL Injection
|
CVE-2016-1000271
|
2024-11-21 11:43 |
2019-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271699
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Insufficient data validation on image data in PDFium in Google Chrome prior to 51.0.2704.63 allowed a remote attacker to perform an out of bounds memory read via a crafted PDF file.
|
CWE-125
Out-of-bounds Read
|
CVE-2016-10403
|
2024-11-21 11:43 |
2019-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271700
|
5.3 |
MEDIUM
Network
|
salesforce ibm redhat
|
tough-cookie api_connect openshift_container_platform
|
NodeJS Tough-Cookie version 2.2.2 contains a Regular Expression Parsing vulnerability in HTTP request Cookie Header parsing that can result in Denial of Service. This attack appear to be exploitable …
|
CWE-20
Improper Input Validation
|
CVE-2016-1000232
|
2024-11-21 11:43 |
2018-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|