Latest CVE Feed
-
9.3
HIGHCVE-2016-10231
An elevation of privilege vulnerability in the Qualcomm sound codec driver. Product: Android. Versions: Android kernel. Android ID: A-33966912. References: QC-CR#1096799.... Read more
Affected Products : android- Published: Apr. 04, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2016-10230
A remote code execution vulnerability in the Qualcomm crypto driver. Product: Android. Versions: Android kernel. Android ID: A-34389927. References: QC-CR#1091408.... Read more
Affected Products : android- Published: Apr. 04, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-10036
Unrestricted file upload vulnerability in ui/artifact/upload in JFrog Artifactory before 4.16 allows remote attackers to (1) deploy an arbitrary servlet application and execute arbitrary code by uploading a war file or (2) possibly write to arbitrary file... Read more
Affected Products : artifactory- Published: May. 01, 2018
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2016-10008
SQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS before 3.7.2 and 4.x before 4.1.1 allows remote authenticated administrators to execute arbitrary SQL commands via the _EXT_STRUCTURE_direction parameter.... Read more
Affected Products : dotcms- Published: Feb. 19, 2018
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2016-10007
SQL injection vulnerability in the "Marketing > Forms" screen in dotCMS before 3.7.2 and 4.x before 4.1.1 allows remote authenticated administrators to execute arbitrary SQL commands via the _EXT_FORM_HANDLER_orderBy parameter.... Read more
Affected Products : dotcms- Published: Feb. 19, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-1000282
Haraka version 2.8.8 and earlier comes with a plugin for processing attachments for zip files. Versions 2.8.8 and earlier can be vulnerable to command injection.... Read more
Affected Products : haraka- Published: Feb. 05, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-1000271
Joomla extension DT Register version before 3.1.12 (Joomla 3.x) / 2.8.18 (Joomla 2.5) contains an SQL injection in "/index.php?controller=calendar&format=raw&cat[0]=SQLi&task=events". This attack appears to be exploitable if the attacker can reach the web... Read more
Affected Products : dt_register- Published: Feb. 04, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUM- Published: Jan. 23, 2020
- Modified: Nov. 21, 2024
-
4.4
MEDIUMCVE-2016-1000236
Node-cookie-signature before 1.0.6 is affected by a timing attack due to the type of comparison used.... Read more
- Published: Nov. 19, 2019
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2016-1000232
NodeJS Tough-Cookie version 2.2.2 contains a Regular Expression Parsing vulnerability in HTTP request Cookie Header parsing that can result in Denial of Service. This attack appear to be exploitable via Custom HTTP header passed by client. This vulnerabil... Read more
- Published: Sep. 05, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUM- Published: Dec. 20, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2016-1000110
The CGIHandler class in Python before 2.7.12 does not protect against the HTTP_PROXY variable name clash in a CGI script, which could allow a remote attacker to redirect HTTP requests.... Read more
- Published: Nov. 27, 2019
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2016-1000109
HHVM does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect ... Read more
Affected Products : hhvm- Published: Feb. 19, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2016-1000108
yaws before 2.0.4 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers... Read more
- Published: Dec. 10, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2016-1000107
inets in Erlang possibly 22.1 and earlier follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an appl... Read more
Affected Products : erlang\/otp- Published: Dec. 10, 2019
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2016-1000104
A security Bypass vulnerability exists in the FcgidPassHeader Proxy in mod_fcgid through 2016-07-07.... Read more
- Published: Dec. 03, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUM- Published: Nov. 06, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-1000030
Pidgin version <2.11.0 contains a vulnerability in X.509 Certificates imports specifically due to improper check of return values from gnutls_x509_crt_init() and gnutls_x509_crt_import() that can result in code execution. This attack appear to be exploita... Read more
- Published: Sep. 05, 2018
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2016-1000029
Tenable Nessus before 6.8 has a stored XSS issue that requires admin-level authentication to the Nessus UI, and would potentially impact other admins (Tenable IDs 5218 and 5269).... Read more
Affected Products : nessus- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2016-1000028
Tenable Nessus before 6.8 has a stored XSS issue that requires admin-level authentication to the Nessus UI, and would only potentially impact other admins. (Tenable ID 5198).... Read more
Affected Products : nessus- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024