Latest CVE Feed
-
6.1
MEDIUMCVE-2016-9409
Cross-site scripting (XSS) vulnerability in the Admin control panel in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via vectors involving pruning logs.... Read more
- Published: Jan. 31, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-9408
Cross-site scripting (XSS) vulnerability in the Mod control panel in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via vectors involving editing users.... Read more
- Published: Jan. 31, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-9407
Cross-site scripting (XSS) vulnerability in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via vectors involving Mod control panel logs.... Read more
- Published: Jan. 31, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-9406
Cross-site scripting (XSS) vulnerability in the User control panel in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Jan. 31, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-9405
Cross-site scripting (XSS) vulnerability in member validation in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Jan. 31, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-9404
Cross-site scripting (XSS) vulnerability in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via vectors related to login.... Read more
- Published: Jan. 31, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-9403
newreply.php in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allows remote attackers to have unspecified impact by leveraging a missing permission check.... Read more
- Published: Jan. 31, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-9402
SQL injection vulnerability in the moderation tool in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to execute arbitrary SQL commands via unspecified vectors.... Read more
- Published: Jan. 31, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-9260
Cross-site scripting (XSS) vulnerability in Tenable Nessus before 6.9 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to handling of .nessus files.... Read more
Affected Products : nessus- Published: Jan. 31, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-8703
Heap-based buffer overflow in the bm_readbody_bmp function in bitmap_io.c in potrace before 1.13 allows remote attackers to have unspecified impact via a crafted BMP image, a different vulnerability than CVE-2016-8698, CVE-2016-8699, CVE-2016-8700, CVE-20... Read more
- Published: Jan. 31, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-8702
Heap-based buffer overflow in the bm_readbody_bmp function in bitmap_io.c in potrace before 1.13 allows remote attackers to have unspecified impact via a crafted BMP image, a different vulnerability than CVE-2016-8698, CVE-2016-8699, CVE-2016-8700, CVE-20... Read more
- Published: Jan. 31, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-8701
Heap-based buffer overflow in the bm_readbody_bmp function in bitmap_io.c in potrace before 1.13 allows remote attackers to have unspecified impact via a crafted BMP image, a different vulnerability than CVE-2016-8698, CVE-2016-8699, CVE-2016-8700, CVE-20... Read more
- Published: Jan. 31, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-8700
Heap-based buffer overflow in the bm_readbody_bmp function in bitmap_io.c in potrace before 1.13 allows remote attackers to have unspecified impact via a crafted BMP image, a different vulnerability than CVE-2016-8698, CVE-2016-8699, CVE-2016-8701, CVE-20... Read more
- Published: Jan. 31, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-8699
Heap-based buffer overflow in the bm_readbody_bmp function in bitmap_io.c in potrace before 1.13 allows remote attackers to have unspecified impact via a crafted BMP image, a different vulnerability than CVE-2016-8698, CVE-2016-8700, CVE-2016-8701, CVE-20... Read more
- Published: Jan. 31, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-8698
Heap-based buffer overflow in the bm_readbody_bmp function in bitmap_io.c in potrace before 1.13 allows remote attackers to have unspecified impact via a crafted BMP image, a different vulnerability than CVE-2016-8699, CVE-2016-8700, CVE-2016-8701, CVE-20... Read more
- Published: Jan. 31, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-8697
The bm_new function in bitmap.h in potrace before 1.13 allows remote attackers to cause a denial of service (divide-by-zero error and crash) via a crafted BMP image.... Read more
Affected Products : potrace- Published: Jan. 31, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-8696
The bm_readbody_bmp function in bitmap_io.c in potrace before 1.13 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted BMP image, a different vulnerability than CVE-2016-8694 and CVE-2016-8695.... Read more
- Published: Jan. 31, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-8695
The bm_readbody_bmp function in bitmap_io.c in potrace before 1.13 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted BMP image, a different vulnerability than CVE-2016-8694 and CVE-2016-8696.... Read more
- Published: Jan. 31, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-8694
The bm_readbody_bmp function in bitmap_io.c in potrace before 1.13 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted BMP image, a different vulnerability than CVE-2016-8695 and CVE-2016-8696.... Read more
- Published: Jan. 31, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-8686
The bm_new function in bitmap.h in potrace 1.13 allows remote attackers to have unspecified impact via a crafted image, which triggers a memory allocation failure.... Read more
Affected Products : potrace- Published: Jan. 31, 2017
- Modified: Apr. 20, 2025