Search Results (24188 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2016-10800 1 Cpanel 1 Cpanel 2024-11-21 N/A
cPanel before 58.0.4 allows demo-mode escape via Site Templates and Boxtrapper API calls (SEC-138).
CVE-2016-10797 1 Cpanel 1 Cpanel 2024-11-21 N/A
cPanel before 58.0.4 allows WHM "Purchase and Install an SSL Certificate" page visitors to list all server domains (SEC-133).
CVE-2016-10794 1 Cpanel 1 Cpanel 2024-11-21 N/A
cPanel before 59.9999.145 allows arbitrary file-read operations because of a multipart form processing error (SEC-154).
CVE-2016-10793 1 Cpanel 1 Cpanel 2024-11-21 N/A
cPanel before 59.9999.145 allows arbitrary code execution due to an incorrect #! in Mail::SPF scripts (SEC-152).
CVE-2016-10790 1 Cpanel 1 Cpanel 2024-11-21 N/A
cPanel before 60.0.25 does not use TLS for HTTP POSTs to listinput.cpanel.net (SEC-192).
CVE-2016-10789 1 Cpanel 1 Cpanel 2024-11-21 N/A
cPanel before 60.0.25 allows code execution via the cpsrvd 403 error response handler (SEC-191).
CVE-2016-10788 1 Cpanel 1 Cpanel 2024-11-21 N/A
cPanel before 60.0.25 allows arbitrary code execution via Maketext in PostgreSQL adminbin (SEC-188).
CVE-2016-10787 1 Cpanel 1 Cpanel 2024-11-21 N/A
The Host Access Control feature in cPanel before 60.0.25 mishandles actionless host.deny entries (SEC-187).
CVE-2016-10786 1 Cpanel 1 Cpanel 2024-11-21 N/A
cPanel before 60.0.25 allows members of the nobody group to read Apache HTTP Server SSL keys (SEC-186).
CVE-2016-10785 1 Cpanel 1 Cpanel 2024-11-21 N/A
cPanel before 60.0.25 allows attackers to discover file contents during file copy operations (SEC-185).
CVE-2016-10775 1 Cpanel 1 Cpanel 2024-11-21 N/A
cPanel before 60.0.25 allows arbitrary file-chown operations via reassign_post_terminate_cruft (SEC-173).
CVE-2016-10771 1 Cpanel 1 Cpanel 2024-11-21 N/A
cPanel before 60.0.25 allows file-create and file-chmod operations during ModSecurity Audit logfile processing (SEC-165).
CVE-2016-10770 1 Cpanel 1 Cpanel 2024-11-21 N/A
cPanel before 60.0.25 allows arbitrary file-overwrite operations during a Roundcube update (SEC-164).
CVE-2016-10768 1 Cpanel 1 Cpanel 2024-11-21 N/A
cPanel before 60.0.25 allows file-overwrite operations during preparation for MySQL upgrades (SEC-161).
CVE-2016-10765 1 Edx 1 Edx-platform 2024-11-21 5.3 Medium
edx-platform before 2016-06-10 allows account activation with a spoofed e-mail address.
CVE-2016-10740 1 Atlassian 1 Crowd 2024-11-21 N/A
Various resources in Atlassian Crowd before version 2.10.1 allow remote attackers with administration rights to learn the passwords of configured LDAP directories by examining the responses to requests for these resources.
CVE-2016-10739 3 Gnu, Opensuse, Redhat 4 Glibc, Leap, Ansible Tower and 1 more 2024-11-21 N/A
In the GNU C Library (aka glibc or libc6) through 2.28, the getaddrinfo function would successfully parse a string that contained an IPv4 address followed by whitespace and arbitrary characters, which could lead applications to incorrectly assume that it had parsed a valid string, without the possibility of embedded HTTP headers or other potentially dangerous substrings.
CVE-2016-10728 1 Suricata-ids 1 Suricata 2024-11-21 N/A
An issue was discovered in Suricata before 3.1.2. If an ICMPv4 error packet is received as the first packet on a flow in the to_client direction, it confuses the rule grouping lookup logic. The toclient inspection will then continue with the wrong rule group. This can lead to missed detection.
CVE-2016-10727 3 Canonical, Gnome, Redhat 3 Ubuntu Linux, Evolution, Enterprise Linux 2024-11-21 N/A
camel/providers/imapx/camel-imapx-server.c in the IMAPx component in GNOME evolution-data-server before 3.21.2 proceeds with cleartext data containing a password if the client wishes to use STARTTLS but the server will not use STARTTLS, which makes it easier for remote attackers to obtain sensitive information by sniffing the network. The server code was intended to report an error and not proceed, but the code was written incorrectly.
CVE-2016-10718 1 Brave 1 Brave Browser 2024-11-21 N/A
Brave Browser before 0.13.0 allows a tab to close itself even if the tab was not opened by a script, resulting in denial of service.