CVE-2016-2042
- EPSS 0.58%
- Veröffentlicht 20.02.2016 01:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request to (1) libraries/phpseclib/Crypt/AES.php or (2) libraries/phpseclib/Crypt/Rijndael.php, which reveals the full path ...
CVE-2016-2041
- EPSS 1.03%
- Veröffentlicht 20.02.2016 01:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not use a constant-time algorithm for comparing CSRF tokens, which makes it easier for remote attackers to bypass intended access restri...
CVE-2016-2040
- EPSS 0.49%
- Veröffentlicht 20.02.2016 01:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 allow remote authenticated users to inject arbitrary web script or HTML via a (1) table name, (2) SET value, (3) s...
CVE-2016-2039
- EPSS 0.38%
- Veröffentlicht 20.02.2016 01:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
libraries/session.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not properly generate CSRF token values, which allows remote attackers to bypass intended access restrictions by predicting a value.
CVE-2016-2038
- EPSS 1.2%
- Veröffentlicht 20.02.2016 01:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error message.
CVE-2016-2270
- EPSS 0.3%
- Veröffentlicht 19.02.2016 16:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Xen 4.6.x and earlier allows local guest administrators to cause a denial of service (host reboot) via vectors related to multiple mappings of MMIO pages with different cachability settings.
CVE-2016-0753
- EPSS 2.33%
- Veröffentlicht 16.02.2016 02:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
Active Model in Ruby on Rails 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 supports the use of instance-level writers for class accessors, which allows remote attackers to bypass intended validation steps via crafted para...
CVE-2016-1526
- EPSS 0.52%
- Veröffentlicht 13.02.2016 02:59:12
- Zuletzt bearbeitet 12.04.2025 10:46:40
The TtfUtil:LocaLookup function in TtfUtil.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, incorrectly validates a size value, which allows remote attackers to obtain sensitive inform...
CVE-2016-1523
- EPSS 0.84%
- Veröffentlicht 13.02.2016 02:59:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
The SillMap::readFace function in FeatureMap.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, mishandles a return value, which allows remote attackers to cause a denial of service (mis...
CVE-2016-1522
- EPSS 1.86%
- Veröffentlicht 13.02.2016 02:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
Code.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, does not consider recursive load calls during a size check, which allows remote attackers to cause a denial of service (heap-based...