CVE-2015-8803
- EPSS 12.34%
- Veröffentlicht 23.02.2016 19:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
The ecc_256_modp function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-256 NIST elliptic curve, which allows attackers to have unspecified impact via unknown...
- EPSS 3.21%
- Veröffentlicht 21.02.2016 18:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
Google Chrome before 48.0.2564.116 allows remote attackers to bypass the Blink Same Origin Policy and a sandbox protection mechanism via unspecified vectors.
CVE-2016-2043
- EPSS 0.39%
- Veröffentlicht 20.02.2016 01:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in the goToFinish1NF function in js/normalization.js in phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote authenticated users to inject arbitrary web script or HTML via a table name to the ...
CVE-2016-2042
- EPSS 0.58%
- Veröffentlicht 20.02.2016 01:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request to (1) libraries/phpseclib/Crypt/AES.php or (2) libraries/phpseclib/Crypt/Rijndael.php, which reveals the full path ...
CVE-2016-2041
- EPSS 1.03%
- Veröffentlicht 20.02.2016 01:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not use a constant-time algorithm for comparing CSRF tokens, which makes it easier for remote attackers to bypass intended access restri...
CVE-2016-2040
- EPSS 0.49%
- Veröffentlicht 20.02.2016 01:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 allow remote authenticated users to inject arbitrary web script or HTML via a (1) table name, (2) SET value, (3) s...
CVE-2016-2039
- EPSS 0.38%
- Veröffentlicht 20.02.2016 01:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
libraries/session.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not properly generate CSRF token values, which allows remote attackers to bypass intended access restrictions by predicting a value.
CVE-2016-2038
- EPSS 1.2%
- Veröffentlicht 20.02.2016 01:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error message.
CVE-2015-7547
- EPSS 93.42%
- Veröffentlicht 18.02.2016 21:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrar...
CVE-2016-0752
- EPSS 92.71%
- Veröffentlicht 16.02.2016 02:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by leveraging an application's unre...