CVE-2016-10000 to CVE-2016-10999
150 CVEs with public proof-of-concept exploits.
- CVE-2016-100051 PoCWebdynpro in SAP Solman 7.1 through 7.31 allows remote attackers to obtain sensitive information via…
- CVE-2016-100061 PoCIn OWASP AntiSamy before 1.5.5, by submitting a specially crafted input (a tag that supports style with active content), you could bypass…
- CVE-2016-100071 PoCSQL injection vulnerability in the "Marketing > Forms" screen in dotCMS before 3.7.2 and 4.x before 4.1.1 allows remote authenticated…
- CVE-2016-100081 PoCSQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS before 3.7.2 and 4.x before 4.1.1 allows remote…
- CVE-2016-100091 PoCUntrusted search path vulnerability in ssh-agent.c in ssh-agent in OpenSSH before 7.4 allows remote attackers to execute arbitrary local…
- CVE-2016-100101 PoCsshd in OpenSSH before 7.4, when privilege separation is not used, creates forwarded Unix-domain sockets as root, which might allow local…
- CVE-2016-100311 PoCWampServer 3.0.6 installs two services called 'wampapache' and 'wampmysqld' with weak file permissions, running with SYSTEM privileges.…
- CVE-2016-10033157 PoCsKEVThe mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail…
- CVE-2016-100346 PoCsThe setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.7.2, and Zend…
- CVE-2016-100362 PoCsUnrestricted file upload vulnerability in ui/artifact/upload in JFrog Artifactory before 4.16 allows remote attackers to (1) deploy an…
- CVE-2016-100431 PoCAn issue was discovered in Radisys MRF Web Panel (SWMS) 9.0.1. The MSM_MACRO_NAME POST parameter in /swms/ms.cgi was discovered to be…
- CVE-2016-10045125 PoCsThe isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently…
- CVE-2016-100721 PoCWampServer 3.0.6 has two files called 'wampmanager.exe' and 'unins000.exe' with a weak ACL for Modify. This could potentially allow an…
- CVE-2016-100734 PoCsThe from method in library/core/class.email.php in Vanilla Forums before 2.3.1 allows remote attackers to spoof the email domain in sent…
- CVE-2016-100746 PoCsThe mail transport (aka Swift_Transport_MailTransport) in Swift Mailer before 5.4.5 might allow remote attackers to pass extra parameters…
- CVE-2016-100791 PoCSAPlpd through 7400.3.11.33 in SAP GUI 7.40 on Windows has a Denial of Service vulnerability (service crash) with a long string to TCP…
- CVE-2016-100811 PoC/usr/bin/shutter in Shutter through 0.93.1 allows user-assisted remote attackers to execute arbitrary commands via a crafted image name…
- CVE-2016-100922 PoCsHeap-based buffer overflow in the readContigStripsIntoBuffer function in tif_unix.c in LibTIFF 4.0.7, 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7,…
- CVE-2016-100932 PoCsInteger overflow in tools/tiffcp.c in LibTIFF 4.0.7, 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7,…
- CVE-2016-100941 PoCOff-by-one error in the t2p_readwrite_pdf_image_tile function in tools/tiff2pdf.c in LibTIFF 4.0.7 allows remote attackers to have…
- CVE-2016-100952 PoCsStack-based buffer overflow in the _TIFFVGetField function in tif_dir.c in LibTIFF 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7,…
- CVE-2016-101082 PoCsUnauthenticated Remote Command injection as root occurs in the Western Digital MyCloud NAS 2.11.142 /web/google_analytics.php URL via a…
- CVE-2016-101141 PoCSQL injection vulnerability in the "aWeb Cart Watching System for Virtuemart" extension before 2.6.1 for Joomla! allows remote attackers…
- CVE-2016-101172 PoCsFirejail does not restrict access to --tmpfs, which allows local users to gain privileges, as demonstrated by mounting over /etc.
- CVE-2016-101182 PoCsFirejail allows local users to truncate /etc/resolv.conf via a chroot command to /.
- CVE-2016-101192 PoCsFirejail uses 0777 permissions when mounting /tmp, which allows local users to gain privileges.
- CVE-2016-101202 PoCsFirejail uses 0777 permissions when mounting (1) /dev, (2) /dev/shm, (3) /var/tmp, or (4) /var/lock, which allows local users to gain…
- CVE-2016-101212 PoCsFirejail uses weak permissions for /dev/shm/firejail and possibly other files, which allows local users to gain privileges.
- CVE-2016-101222 PoCsFirejail does not properly clean environment variables, which allows local users to gain privileges.
- CVE-2016-101232 PoCsFirejail allows --chroot when seccomp is not supported, which might allow local users to gain privileges.
- CVE-2016-101345 PoCsSQL injection vulnerability in Zabbix before 2.2.14 and 3.0 before 3.0.4 allows remote attackers to execute arbitrary SQL commands via the…
- CVE-2016-101401 PoCInformation disclosure and authentication bypass vulnerability exists in the Apache HTTP Server configuration bundled with ZoneMinder…
- CVE-2016-101481 PoCThe wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 makes a get_plugin_data call before…
- CVE-2016-101561 PoCA flaw in systemd v228 in /src/basic/fs-util.c caused world writable suid files to be created when using the systemd timers features,…
- CVE-2016-101731 PoCDirectory traversal vulnerability in the minitar before 0.6 and archive-tar-minitar 0.5.2 gems for Ruby allows remote attackers to write…
- CVE-2016-101745 PoCsKEVThe NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL…
- CVE-2016-101753 PoCsThe NETGEAR WNR2000v5 router leaks its serial number when performing a request to the /BRS_netgear_success.html URI. This serial number…
- CVE-2016-101763 PoCsThe NETGEAR WNR2000v5 router allows an administrator to perform sensitive actions by invoking the apply.cgi URL on the web server of the…
- CVE-2016-101771 PoCAn issue was discovered on the D-Link DWR-932B router. Undocumented TELNET and SSH services provide logins to admin with the password…
- CVE-2016-101781 PoCAn issue was discovered on the D-Link DWR-932B router. HELODBG on port 39889 (UDP) launches the "/sbin/telnetd -l /bin/sh" command.
- CVE-2016-101791 PoCAn issue was discovered on the D-Link DWR-932B router. There is a hardcoded WPS PIN of 28296607.
- CVE-2016-101801 PoCAn issue was discovered on the D-Link DWR-932B router. WPS PIN generation is based on srand(time(0)) seeding.
- CVE-2016-101811 PoCAn issue was discovered on the D-Link DWR-932B router. qmiweb provides sensitive information for CfgType=get_homeCfg requests.
- CVE-2016-101821 PoCAn issue was discovered on the D-Link DWR-932B router. qmiweb allows command injection with ` characters.
- CVE-2016-101831 PoCAn issue was discovered on the D-Link DWR-932B router. qmiweb allows directory listing with ../ traversal.
- CVE-2016-101841 PoCAn issue was discovered on the D-Link DWR-932B router. qmiweb allows file reading with ..%2f traversal.
- CVE-2016-101851 PoCAn issue was discovered on the D-Link DWR-932B router. A secure_mode=no line exists in /var/miniupnpd.conf.
- CVE-2016-101861 PoCAn issue was discovered on the D-Link DWR-932B router. /var/miniupnpd.conf has no deny rules.
- CVE-2016-101902 PoCsHeap-based buffer overflow in libavformat/http.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2…
- CVE-2016-101911 PoCHeap-based buffer overflow in libavformat/rtmppkt.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before…
- CVE-2016-101961 PoCStack-based buffer overflow in the evutil_parse_sockaddr_port function in evutil.c in libevent before 2.1.6-beta allows attackers to cause…
- CVE-2016-101971 PoCThe search_make_new function in evdns.c in libevent before 2.1.6-beta allows attackers to cause a denial of service (out-of-bounds read)…
- CVE-2016-102041 PoCSQL injection vulnerability in Zoneminder 1.30 and earlier allows remote attackers to execute arbitrary SQL commands via the limit…
- CVE-2016-102111 PoClibyara/grammar.y in YARA 3.5.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted…
- CVE-2016-102171 PoCThe pdf14_open function in base/gdevp14.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service…
- CVE-2016-102181 PoCThe pdf14_pop_transparency_group function in base/gdevp14.c in the PDF Transparency module in Artifex Software, Inc. Ghostscript 9.20…
- CVE-2016-102191 PoCThe intersect function in base/gxfill.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service…
- CVE-2016-102201 PoCThe gs_makewordimagedevice function in base/gsdevmem.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a…
- CVE-2016-102211 PoCThe count_entries function in pdf-layer.c in Artifex Software, Inc. MuPDF 1.10a allows remote attackers to cause a denial of service…
- CVE-2016-102252 PoCsThe sunxi-debug driver in Allwinner 3.4 legacy kernel for H3, A83T and H8 devices allows local users to gain root privileges by sending…
- CVE-2016-102431 PoCTeX Live allows remote attackers to execute arbitrary commands by leveraging inclusion of mpost in shell_escape_commands in the texmf.cnf…
- CVE-2016-102491 PoCInteger overflow in the jpc_dec_tiledecode function in jpc_dec.c in JasPer before 1.900.12 allows remote attackers to have unspecified…
- CVE-2016-102501 PoCThe jp2_colr_destroy function in jp2_cod.c in JasPer before 1.900.13 allows remote attackers to cause a denial of service (NULL pointer…
- CVE-2016-102511 PoCInteger overflow in the jpc_pi_nextcprl function in jpc_t2cod.c in JasPer before 1.900.20 allows remote attackers to have unspecified…
- CVE-2016-102581 PoCUnrestricted file upload vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles. A malicious…
- CVE-2016-102772 PoCsAn elevation of privilege vulnerability in the Motorola bootloader could enable a local malicious application to execute arbitrary code…
- CVE-2016-103171 PoCThe fill_threshhold_buffer function in base/gxht_thresh.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a…
- CVE-2016-103201 PoCtextract before 1.5.0 allows OS Command Injection attacks via a filename in a call to the process function. This may be a remote attack if…
- CVE-2016-103671 PoCIn Opsview Monitor Pro (Prior to 5.1.0.162300841, prior to 5.0.2.27475, prior to 4.6.4.162391051, and 4.5.x without a certain 2016…
- CVE-2016-103681 PoCOpen redirect vulnerability in Opsview Monitor Pro (Prior to 5.1.0.162300841, prior to 5.0.2.27475, prior to 4.6.4.162391051, and 4.5.x…
- CVE-2016-103701 PoCAn issue was discovered on OnePlus devices such as the 3T. The OnePlus OTA Updater pushes the signed-OTA image over HTTP without TLS.…
- CVE-2016-103723 PoCsThe Eir D1000 modem does not properly restrict the TR-064 protocol, which allows remote attackers to execute arbitrary commands via TCP…
- CVE-2016-103781 PoCe107 2.1.1 allows SQL injection by remote authenticated administrators via the pagelist parameter to e107_admin/menus.php, related to the…
- CVE-2016-103791 PoCThe VirtueMart com_virtuemart component 3.0.14 for Joomla! allows SQL injection by remote authenticated administrators via the…
- CVE-2016-104011 PoCZyXEL PK5001Z devices have zyad5001 as the su password, which makes it easier for remote attackers to obtain root access if a non-root…
- CVE-2016-105041 PoCHeap-based buffer overflow vulnerability in the opj_mqc_byteout function in mqc.c in OpenJPEG before 2.2.0 allows remote attackers to…
- CVE-2016-105111 PoCThe Twitter iOS client versions 6.62 and 6.62.1 fail to validate Twitter's server certificates for the /1.1/help/settings.json…
- CVE-2016-105201 PoCjadedown is vulnerable to regular expression denial of service (ReDoS) when certain types of user input is passed in.
- CVE-2016-105211 PoCjshamcrest is vulnerable to regular expression denial of service (ReDoS) when certain types of user input is passed in to the emailAddress…
- CVE-2016-105231 PoCMQTT before 3.4.6 and 4.0.x before 4.0.5 allows specifically crafted MQTT packets to crash the application, making a DoS attack feasible…
- CVE-2016-105281 PoCrestafary is a REpresentful State Transfer API for Creating, Reading, Using, Deleting files on a server from the web. Restafary before…
- CVE-2016-105311 PoCmarked is an application that is meant to parse and compile markdown. Due to the way that marked 0.3.5 and earlier parses input,…
- CVE-2016-105331 PoCexpress-restify-mongoose is a module to easily create a flexible REST interface for mongoose models. express-restify-mongoose 2.4.2 and…
- CVE-2016-105381 PoCThe package `node-cli` before 1.0.0 insecurely uses the lock_file and log_file. Both of these are temporary, but it allows the starting…
- CVE-2016-105411 PoCThe npm module "shell-quote" 1.6.0 and earlier cannot correctly escape ">" and "<" operator used for redirection in shell. Applications…
- CVE-2016-105421 PoCws is a "simple to use, blazing fast and thoroughly tested websocket client, server and console for node.js, up-to-date against RFC-6455".…
- CVE-2016-105471 PoCNunjucks is a full featured templating engine for JavaScript. Versions 2.4.2 and lower have a cross site scripting (XSS) vulnerability in…
- CVE-2016-105481 PoCArbitrary code execution is possible in reduce-css-calc node module <=1.2.4 through crafted css. This makes cross sites scripting (XSS)…
- CVE-2016-105553 PoCsSince "algorithm" isn't enforced in jwt.decode()in jwt-simple 0.3.0 and earlier, a malicious user could choose what algorithm is sent sent…
- CVE-2016-105561 PoCsequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server…
- CVE-2016-107081 PoCsshd in OpenSSH before 7.4 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an…
- CVE-2016-107093 PoCspfSense before 2.3 allows remote authenticated users to execute arbitrary OS commands via a '|' character in the status_rrd_graph_img.php…
- CVE-2016-107171 PoCA vulnerability in the encryption and permission implementation of Malwarebytes Anti-Malware consumer version 2.2.1 and prior (fixed in…
- CVE-2016-107181 PoCBrave Browser before 0.13.0 allows a tab to close itself even if the tab was not opened by a script, resulting in denial of service.
- CVE-2016-107191 PoCTP-Link Archer CR-700 1.0.6 devices have an XSS vulnerability that can be introduced into the admin account through a DHCP request,…
- CVE-2016-107221 PoCpartclone.fat in Partclone before 0.2.88 is prone to a heap-based buffer overflow vulnerability due to insufficient validation of the FAT…
- CVE-2016-107261 PoCThe XMLUI feature in DSpace before 3.6, 4.x before 4.5, and 5.x before 5.5 allows directory traversal via the themes/ path in an attack…
- CVE-2016-107281 PoCAn issue was discovered in Suricata before 3.1.2. If an ICMPv4 error packet is received as the first packet on a flow in the to_client…
- CVE-2016-107291 PoCAn issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. The "runtar" setuid…
- CVE-2016-107301 PoCAn issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. Amstar is an Amanda…
- CVE-2016-107352 PoCsIn Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute, a different vulnerability…
- CVE-2016-107361 PoCThe "Social Pug - Easy Social Share Buttons" plugin before 1.2.6 for WordPress allows XSS via the wp-admin/admin.php?page=dpsp-toolkit…
- CVE-2016-107371 PoCSerendipity 2.0.4 has XSS via the serendipity_admin.php serendipity[body] parameter.
- CVE-2016-107381 PoCZenbership v107 has CSRF via admin/cp-functions/event-add.php.
- CVE-2016-107421 PoCZabbix before 2.2.21rc1, 3.x before 3.0.13rc1, 3.1.x and 3.2.x before 3.2.10rc1, and 3.3.x and 3.4.x before 3.4.4rc1 allows open redirect…
- CVE-2016-107492 PoCsparse_string in cJSON.c in cJSON before 2016-10-02 has a buffer over-read, as demonstrated by a string that begins with a " character and…
- CVE-2016-107631 PoCThe CampTix Event Ticketing plugin before 1.5 for WordPress allows XSS in the admin section via a ticket title or body.
- CVE-2016-108621 PoCNeet AirStream NAS1.1 devices have a password of ifconfig for the root account. This cannot be changed via the configuration page.
- CVE-2016-108641 PoCNETGEAR EX7000 V1.0.0.42_1.0.94 devices allow XSS via the SSID.
- CVE-2016-108651 PoCThe Lightbox Plus Colorbox plugin through 2.7.2 for WordPress has cross-site request forgery (CSRF) via…
- CVE-2016-109246 PoCsThe ebook-download plugin before 1.2 for WordPress has directory traversal.
- CVE-2016-109382 PoCsThe copy-me plugin 1.0.0 for WordPress has CSRF for copying non-public posts to a public location.
- CVE-2016-109391 PoCThe xtremelocator plugin 1.5 for WordPress has SQL injection via the id parameter.
- CVE-2016-109402 PoCsThe zm-gallery plugin 1.0 for WordPress has SQL injection via the order parameter.
- CVE-2016-109432 PoCsThe zx-csv-upload plugin 1 for WordPress has SQL injection via the id parameter.
- CVE-2016-109441 PoCThe multisite-post-duplicator plugin before 1.1.3 for WordPress has wp-admin/tools.php?page=mpd CSRF.
- CVE-2016-109461 PoCThe wp-d3 plugin before 2.4.1 for WordPress has CSRF.
- CVE-2016-109471 PoCThe Post Indexer plugin before 3.0.6.2 for WordPress has SQL injection via the period parameter by a super admin.
- CVE-2016-109481 PoCThe Post Indexer plugin before 3.0.6.2 for WordPress has incorrect handling of data passed to the unserialize function.
- CVE-2016-109491 PoCThe Relevanssi Premium plugin before 1.14.6.1 for WordPress has SQL injection with resultant unsafe unserialization.
- CVE-2016-109501 PoCThe sirv plugin before 1.3.2 for WordPress has SQL injection via the id parameter.
- CVE-2016-109511 PoCThe fs-shopping-cart plugin 2.07.02 for WordPress has SQL injection via the pid parameter.
- CVE-2016-109521 PoCThe quotes-collection plugin before 2.0.6 for WordPress has XSS via the wp-admin/admin.php?page=quotes-collection page parameter.
- CVE-2016-109551 PoCThe cysteme-finder plugin before 1.4 for WordPress has unrestricted file upload because of incorrect session tracking.
- CVE-2016-109565 PoCsThe mail-masta plugin 1.0 for WordPress has local file inclusion in count_of_send.php and csvexport.php.
- CVE-2016-109572 PoCsThe Akal theme through 2016-08-22 for WordPress has XSS via the framework/brad-shortcodes/tinymce/preview.php sc parameter.
- CVE-2016-109581 PoCThe estatik plugin before 2.3.0 for WordPress has unauthenticated arbitrary file upload via es_media_images[] to wp-admin/admin-ajax.php.
- CVE-2016-109591 PoCThe estatik plugin before 2.3.1 for WordPress has authenticated arbitrary file upload (exploitable with CSRF) via es_media_images[] to…
- CVE-2016-109602 PoCsThe wsecure plugin before 2.4 for WordPress has remote code execution via shell metacharacters in the wsecure-config.php publish parameter.
- CVE-2016-109611 PoCThe colorway theme before 3.4.2 for WordPress has XSS via the contactName parameter.
- CVE-2016-109641 PoCThe dwnldr plugin before 1.01 for WordPress has XSS via the User-Agent HTTP header.
- CVE-2016-109651 PoCThe real3d-flipbook-lite plugin 1.0 for WordPress has deleteBook=../ directory traversal for file deletion.
- CVE-2016-109661 PoCThe real3d-flipbook-lite plugin 1.0 for WordPress has bookName=../ directory traversal for file upload.
- CVE-2016-109671 PoCThe real3d-flipbook-lite plugin 1.0 for WordPress has XSS via the wp-content/plugins/real3d-flipbook/includes/flipbooks.php bookId…
- CVE-2016-109721 PoCThe newspaper theme before 6.7.2 for WordPress has a lack of options access control via td_ajax_update_panel.
- CVE-2016-109732 PoCsThe Brafton plugin before 3.4.8 for WordPress has XSS via the wp-admin/admin.php?page=BraftonArticleLoader tab parameter to…
- CVE-2016-109762 PoCsThe safe-editor plugin before 1.2 for WordPress has no se_save authentication, with resultant XSS.
- CVE-2016-109801 PoCThe kento-post-view-counter plugin through 2.8 for WordPress has XSS via kento_pvc_geo.
- CVE-2016-109831 PoCThe ghost plugin before 0.5.6 for WordPress has no access control for wp-admin/tools.php?ghostexport=true downloads of exported data.
- CVE-2016-109841 PoCThe echosign plugin before 1.2 for WordPress has XSS via the inc.php page parameter.
- CVE-2016-109851 PoCThe echosign plugin before 1.2 for WordPress has XSS via the templates/add_templates.php id parameter.
- CVE-2016-109861 PoCThe tweet-wheel plugin before 1.0.3.3 for WordPress has XSS via consumer_key, consumer_secret, access_token, and access_token_secret.
- CVE-2016-109871 PoCThe persian-woocommerce-sms plugin before 3.3.4 for WordPress has ps_sms_numbers XSS.
- CVE-2016-109901 PoCThe wp-cerber plugin before 2.7 for WordPress has XSS via the X-Forwarded-For HTTP header.
- CVE-2016-109921 PoCThe music-store plugin before 1.0.43 for WordPress has XSS via the wp-admin/admin.php?page=music-store-menu-reports from_year parameter.
- CVE-2016-109934 PoCsThe ScoreMe theme through 2016-04-01 for WordPress has XSS via the s parameter.
- CVE-2016-109941 PoCThe Truemag theme 2016 Q2 for WordPress has XSS via the s parameter.
- CVE-2016-109971 PoCThe beauty-premium theme 1.0.8 for WordPress has CSRF with resultant arbitrary file upload in includes/sendmail.php.
- CVE-2016-109981 PoCThe ocim-mp3 plugin through 2016-03-07 for WordPress has wp-content/plugins/ocim-mp3/source/pages.php?id= XSS.
- CVE-2016-109991 PoCThe Goodnews theme through 2016-02-28 for WordPress has XSS via the s parameter.