CVE-2015-8080
- EPSS 2.24%
- Veröffentlicht 13.04.2016 15:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
Integer overflow in the getnum function in lua_struct.c in Redis 2.8.x before 2.8.24 and 3.0.x before 3.0.6 allows context-dependent attackers with permission to run Lua code in a Redis session to cause a denial of service (memory corruption and appl...
CVE-2015-0861
- EPSS 0.25%
- Veröffentlicht 13.04.2016 15:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
model/modelstorage.py in trytond 3.2.x before 3.2.10, 3.4.x before 3.4.8, 3.6.x before 3.6.5, and 3.8.x before 3.8.1 allows remote authenticated users to bypass intended access restrictions and write to arbitrary fields via a sequence of records.
CVE-2014-6276
- EPSS 0.13%
- Veröffentlicht 13.04.2016 14:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
schema.py in Roundup before 1.5.1 does not properly limit attributes included in default user permissions, which might allow remote authenticated users to obtain sensitive user information by viewing user details.
CVE-2016-2118
- EPSS 78.52%
- Veröffentlicht 12.04.2016 23:59:37
- Zuletzt bearbeitet 12.04.2025 10:46:40
The MS-SAMR and MS-LSAD protocol implementations in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 mishandle DCERPC connections, which allows man-in-the-middle attackers to perform protocol-downgrade attacks and impersona...
CVE-2016-3171
- EPSS 8.22%
- Veröffentlicht 12.04.2016 15:59:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
Drupal 6.x before 6.38, when used with PHP before 5.4.45, 5.5.x before 5.5.29, or 5.6.x before 5.6.13, might allow remote attackers to execute arbitrary code via vectors related to session data truncation.
CVE-2016-3170
- EPSS 0.5%
- Veröffentlicht 12.04.2016 15:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
The "have you forgotten your password" links in the User module in Drupal 7.x before 7.43 and 8.x before 8.0.4 allow remote attackers to obtain sensitive username information by leveraging a configuration that permits using an email address to login ...
CVE-2016-3169
- EPSS 1.02%
- Veröffentlicht 12.04.2016 15:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
The User module in Drupal 6.x before 6.38 and 7.x before 7.43 allows remote attackers to gain privileges by leveraging contributed or custom code that calls the user_save function with an explicit category and loads all roles into the array.
CVE-2016-3168
- EPSS 0.54%
- Veröffentlicht 12.04.2016 15:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The System module in Drupal 6.x before 6.38 and 7.x before 7.43 might allow remote attackers to hijack the authentication of site administrators for requests that download and run files with arbitrary JSON-encoded content, aka a "reflected file downl...
CVE-2016-3166
- EPSS 0.5%
- Veröffentlicht 12.04.2016 15:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
CRLF injection vulnerability in the drupal_set_header function in Drupal 6.x before 6.38, when used with PHP before 5.1.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks by leveraging a module tha...
CVE-2016-3167
- EPSS 0.63%
- Veröffentlicht 12.04.2016 15:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
Open redirect vulnerability in the drupal_goto function in Drupal 6.x before 6.38, when used with PHP before 5.4.7, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a double-encoded URL in the "destina...