Show filters
774 Total Results
Displaying 491-500 of 774
Sort by:
Attacker Value
Unknown
CVE-2016-6601
Disclosure Date: January 23, 2017 (last updated November 25, 2024)
Directory traversal vulnerability in the file download functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to read arbitrary files via a .. (dot dot) in the fileName parameter to servlets/FetchFile.
0
Attacker Value
Unknown
CVE-2016-10034
Disclosure Date: December 30, 2016 (last updated November 25, 2024)
The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.7.2, and Zend Framework before 2.4.11 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted e-mail address.
0
Attacker Value
Unknown
CVE-2016-9878
Disclosure Date: December 29, 2016 (last updated November 25, 2024)
An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5. Paths provided to the ResourceServlet were not properly sanitized and as a result exposed to directory traversal attacks.
0
Attacker Value
Unknown
CVE-2016-7172
Disclosure Date: December 21, 2016 (last updated November 25, 2024)
NetApp Snap Creator Framework before 4.3.1 discloses sensitive information which could be viewed by an unauthorized user.
0
Attacker Value
Unknown
CVE-2016-7270
Disclosure Date: December 20, 2016 (last updated November 25, 2024)
The Data Provider for SQL Server in Microsoft .NET Framework 4.6.2 mishandles a developer-supplied key, which allows remote attackers to bypass the Always Encrypted protection mechanism and obtain sensitive cleartext information by leveraging key guessability, aka ".NET Information Disclosure Vulnerability."
0
Attacker Value
Unknown
CVE-2016-9835
Disclosure Date: December 05, 2016 (last updated November 25, 2024)
Directory traversal vulnerability in file "jcss.php" in Zikula 1.3.x before 1.3.11 and 1.4.x before 1.4.4 on Windows allows a remote attacker to launch a PHP object injection by uploading a serialized file.
0
Attacker Value
Unknown
CVE-2016-5524
Disclosure Date: October 25, 2016 (last updated November 25, 2024)
Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote attackers to affect confidentiality via unknown vectors, a different vulnerability than CVE-2016-5527.
0
Attacker Value
Unknown
CVE-2016-5534
Disclosure Date: October 25, 2016 (last updated November 25, 2024)
Unspecified vulnerability in the Siebel Apps - Customer Order Management component in Oracle Siebel CRM 16.1 allows remote authenticated users to affect confidentiality via unknown vectors.
0
Attacker Value
Unknown
CVE-2016-5527
Disclosure Date: October 25, 2016 (last updated November 25, 2024)
Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote attackers to affect confidentiality via unknown vectors, a different vulnerability than CVE-2016-5524.
0
Attacker Value
Unknown
CVE-2016-5526
Disclosure Date: October 25, 2016 (last updated November 25, 2024)
Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Apache Tomcat.
0