Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 79 096

Количество 79 096

ubuntu логотип

CVE-2016-4434

почти 9 лет назад

Apache Tika before 1.13 does not properly initialize the XML parser or choose handlers, which might allow remote attackers to conduct XML External Entity (XXE) attacks via vectors involving (1) spreadsheets in OOXML files and (2) XMP metadata in PDF and other file formats, a related issue to CVE-2016-2175.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2016-4433

около 10 лет назад

Apache Struts 2 2.3.20 through 2.3.28.1 allows remote attackers to bypass intended access restrictions and conduct redirection attacks via a crafted request.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2016-4432

больше 10 лет назад

The AMQP 0-8, 0-9, 0-91, and 0-10 connection handling in Apache Qpid Java before 6.0.3 might allow remote attackers to bypass authentication and consequently perform actions via vectors related to connection state logging.

CVSS3: 9.1
EPSS: Низкий
ubuntu логотип

CVE-2016-4431

около 10 лет назад

Apache Struts 2 2.3.20 through 2.3.28.1 allows remote attackers to bypass intended access restrictions and conduct redirection attacks by leveraging a default method.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2016-4430

около 10 лет назад

Apache Struts 2 2.3.20 through 2.3.28.1 mishandles token validation, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks via unspecified vectors.

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2016-4429

больше 10 лет назад

Stack-based buffer overflow in the clntudp_call function in sunrpc/clnt_udp.c in the GNU C Library (aka glibc or libc6) allows remote servers to cause a denial of service (crash) or possibly unspecified other impact via a flood of crafted ICMP and UDP packets.

CVSS3: 5.9
EPSS: Низкий
ubuntu логотип

CVE-2016-4428

около 10 лет назад

Cross-site scripting (XSS) vulnerability in OpenStack Dashboard (Horizon) 8.0.1 and earlier and 9.0.0 through 9.0.1 allows remote authenticated users to inject arbitrary web script or HTML by injecting an AngularJS template in a dashboard form.

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2016-4425

больше 10 лет назад

Jansson 2.7 and earlier allows context-dependent attackers to cause a denial of service (deep recursion, stack consumption, and crash) via crafted JSON data.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2016-4423

больше 10 лет назад

The attemptAuthentication function in Component/Security/Http/Firewall/UsernamePasswordFormAuthenticationListener.php in Symfony before 2.3.41, 2.7.x before 2.7.13, 2.8.x before 2.8.6, and 3.0.x before 3.0.6 does not limit the length of a username stored in a session, which allows remote attackers to cause a denial of service (session storage consumption) via a series of authentication attempts with long, non-existent usernames.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2016-4422

больше 10 лет назад

The pam_sm_authenticate function in pam_sshauth.c in libpam-sshauth might allow context-dependent attackers to bypass authentication or gain privileges via a system user account.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2016-4421

больше 10 лет назад

epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wireshark 1.12.x before 1.12.10 and 2.x before 2.0.2 allows remote attackers to cause a denial of service (deep recursion, stack consumption, and application crash) via a packet that specifies deeply nested data.

CVSS3: 5.9
EPSS: Низкий
ubuntu логотип

CVE-2016-4420

больше 10 лет назад

The NFS dissector in Wireshark 2.x before 2.0.2 allows remote attackers to cause a denial of service (application crash) via a crafted packet.

CVSS3: 5.9
EPSS: Низкий
ubuntu логотип

CVE-2016-4419

больше 10 лет назад

epan/dissectors/packet-spice.c in the SPICE dissector in Wireshark 2.x before 2.0.2 mishandles capability data, which allows remote attackers to cause a denial of service (large loop) via a crafted packet.

CVSS3: 5.9
EPSS: Низкий
ubuntu логотип

CVE-2016-4418

больше 10 лет назад

epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wireshark 1.12.x before 1.12.10 and 2.x before 2.0.2 allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted packet that triggers an empty set.

CVSS3: 5.9
EPSS: Низкий
ubuntu логотип

CVE-2016-4417

больше 10 лет назад

Off-by-one error in epan/dissectors/packet-gsm_abis_oml.c in the GSM A-bis OML dissector in Wireshark 1.12.x before 1.12.10 and 2.x before 2.0.2 allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted packet that triggers a 0xff tag value.

CVSS3: 5.9
EPSS: Низкий
ubuntu логотип

CVE-2016-4416

больше 10 лет назад

epan/dissectors/packet-ieee80211.c in the IEEE 802.11 dissector in Wireshark 2.x before 2.0.2 mishandles the Grouping subfield, which allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted packet.

CVSS3: 5.9
EPSS: Низкий
ubuntu логотип

CVE-2016-4415

больше 10 лет назад

wiretap/vwr.c in the Ixia IxVeriWave file parser in Wireshark 2.x before 2.0.2 incorrectly increases a certain octet count, which allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) via a crafted file.

CVSS3: 5.9
EPSS: Низкий
ubuntu логотип

CVE-2016-4414

больше 10 лет назад

The onReadyRead function in core/coreauthhandler.cpp in Quassel before 0.12.4 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via invalid handshake data.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2016-4412

почти 10 лет назад

An issue was discovered in phpMyAdmin. A user can be tricked into following a link leading to phpMyAdmin, which after authentication redirects to another malicious site. The attacker must sniff the user's valid phpMyAdmin token. All 4.0.x versions (prior to 4.0.10.16) are affected.

CVSS3: 4.4
EPSS: Низкий
ubuntu логотип

CVE-2016-4383

около 9 лет назад

The glance-manage db in all versions of HPE Helion Openstack Glance allows deleted image ids to be reassigned, which allows remote authenticated users to cause other users to boot into a modified image without notification of the change.

CVSS3: 8.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2016-4434

Apache Tika before 1.13 does not properly initialize the XML parser or choose handlers, which might allow remote attackers to conduct XML External Entity (XXE) attacks via vectors involving (1) spreadsheets in OOXML files and (2) XMP metadata in PDF and other file formats, a related issue to CVE-2016-2175.

CVSS3: 7.8
4%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2016-4433

Apache Struts 2 2.3.20 through 2.3.28.1 allows remote attackers to bypass intended access restrictions and conduct redirection attacks via a crafted request.

CVSS3: 7.5
10%
Низкий
около 10 лет назад
ubuntu логотип
CVE-2016-4432

The AMQP 0-8, 0-9, 0-91, and 0-10 connection handling in Apache Qpid Java before 6.0.3 might allow remote attackers to bypass authentication and consequently perform actions via vectors related to connection state logging.

CVSS3: 9.1
8%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2016-4431

Apache Struts 2 2.3.20 through 2.3.28.1 allows remote attackers to bypass intended access restrictions and conduct redirection attacks by leveraging a default method.

CVSS3: 7.5
10%
Низкий
около 10 лет назад
ubuntu логотип
CVE-2016-4430

Apache Struts 2 2.3.20 through 2.3.28.1 mishandles token validation, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks via unspecified vectors.

CVSS3: 8.8
4%
Низкий
около 10 лет назад
ubuntu логотип
CVE-2016-4429

Stack-based buffer overflow in the clntudp_call function in sunrpc/clnt_udp.c in the GNU C Library (aka glibc or libc6) allows remote servers to cause a denial of service (crash) or possibly unspecified other impact via a flood of crafted ICMP and UDP packets.

CVSS3: 5.9
5%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2016-4428

Cross-site scripting (XSS) vulnerability in OpenStack Dashboard (Horizon) 8.0.1 and earlier and 9.0.0 through 9.0.1 allows remote authenticated users to inject arbitrary web script or HTML by injecting an AngularJS template in a dashboard form.

CVSS3: 5.4
2%
Низкий
около 10 лет назад
ubuntu логотип
CVE-2016-4425

Jansson 2.7 and earlier allows context-dependent attackers to cause a denial of service (deep recursion, stack consumption, and crash) via crafted JSON data.

CVSS3: 6.5
2%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2016-4423

The attemptAuthentication function in Component/Security/Http/Firewall/UsernamePasswordFormAuthenticationListener.php in Symfony before 2.3.41, 2.7.x before 2.7.13, 2.8.x before 2.8.6, and 3.0.x before 3.0.6 does not limit the length of a username stored in a session, which allows remote attackers to cause a denial of service (session storage consumption) via a series of authentication attempts with long, non-existent usernames.

CVSS3: 7.5
2%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2016-4422

The pam_sm_authenticate function in pam_sshauth.c in libpam-sshauth might allow context-dependent attackers to bypass authentication or gain privileges via a system user account.

CVSS3: 9.8
2%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2016-4421

epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wireshark 1.12.x before 1.12.10 and 2.x before 2.0.2 allows remote attackers to cause a denial of service (deep recursion, stack consumption, and application crash) via a packet that specifies deeply nested data.

CVSS3: 5.9
1%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2016-4420

The NFS dissector in Wireshark 2.x before 2.0.2 allows remote attackers to cause a denial of service (application crash) via a crafted packet.

CVSS3: 5.9
1%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2016-4419

epan/dissectors/packet-spice.c in the SPICE dissector in Wireshark 2.x before 2.0.2 mishandles capability data, which allows remote attackers to cause a denial of service (large loop) via a crafted packet.

CVSS3: 5.9
1%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2016-4418

epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wireshark 1.12.x before 1.12.10 and 2.x before 2.0.2 allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted packet that triggers an empty set.

CVSS3: 5.9
1%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2016-4417

Off-by-one error in epan/dissectors/packet-gsm_abis_oml.c in the GSM A-bis OML dissector in Wireshark 1.12.x before 1.12.10 and 2.x before 2.0.2 allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted packet that triggers a 0xff tag value.

CVSS3: 5.9
1%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2016-4416

epan/dissectors/packet-ieee80211.c in the IEEE 802.11 dissector in Wireshark 2.x before 2.0.2 mishandles the Grouping subfield, which allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted packet.

CVSS3: 5.9
1%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2016-4415

wiretap/vwr.c in the Ixia IxVeriWave file parser in Wireshark 2.x before 2.0.2 incorrectly increases a certain octet count, which allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) via a crafted file.

CVSS3: 5.9
2%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2016-4414

The onReadyRead function in core/coreauthhandler.cpp in Quassel before 0.12.4 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via invalid handshake data.

CVSS3: 7.5
3%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2016-4412

An issue was discovered in phpMyAdmin. A user can be tricked into following a link leading to phpMyAdmin, which after authentication redirects to another malicious site. The attacker must sniff the user's valid phpMyAdmin token. All 4.0.x versions (prior to 4.0.10.16) are affected.

CVSS3: 4.4
1%
Низкий
почти 10 лет назад
ubuntu логотип
CVE-2016-4383

The glance-manage db in all versions of HPE Helion Openstack Glance allows deleted image ids to be reassigned, which allows remote authenticated users to cause other users to boot into a modified image without notification of the change.

CVSS3: 8.4
3%
Низкий
около 9 лет назад

Уязвимостей на страницу