|
1271
|
6.5
7.5
|
MEDIUM
Network
|
PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to read or write to arbitrary files via crafted i…
|
CWE-20
Improper Input Validation
|
CVE-2015-4598
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:6.0:*
|
|
|
|
|
2024-11-21 11:31
2016-05-16
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1272
|
5.3
5.0
|
MEDIUM
Network
|
PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to read arbitrary files via crafted input to an ap…
|
CWE-200 CWE-254
Information Exposure 7PK - Security Features
|
CVE-2015-3412
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:6.0:*
|
|
|
|
|
2024-11-21 11:29
2016-05-16
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1273
|
6.5
6.4
|
MEDIUM
Network
|
PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to read or write to arbitrary files via crafted in…
|
CWE-20
Improper Input Validation
|
CVE-2015-3411
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:6.0:*
|
|
|
|
|
2024-11-21 11:29
2016-05-16
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1274
|
5.5
2.1
|
MEDIUM
Local
|
The VFS subsystem in the Linux kernel 3.x provides an incomplete set of requirements for setattr operations that underspecifies removing extended privilege attributes, which allows local users to cau…
|
CWE-552
Files or Directories Accessible to External Parties
|
CVE-2015-1350
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:6.0:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2024-11-21 11:25
2016-05-2
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1275
|
7.8
6.9
|
HIGH
Local
|
The fork implementation in the Linux kernel before 4.5 on s390 platforms mishandles the case of four page-table levels, which allows local users to cause a denial of service (system crash) or possibl…
|
CWE-20
Improper Input Validation
|
CVE-2016-2143
|
cpe:2.3:o:redhat:enterprise_linux:7.0:*
|
|
|
|
|
2024-11-21 11:47
2016-04-28
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1276
|
5.5
3.5
|
MEDIUM
Local
|
Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows local users…
|
NVD-CWE-noinfo
|
CVE-2016-0666
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:6.0:*
|
|
|
|
|
2024-11-21 11:42
2016-04-21
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1277
|
5.5
3.5
|
MEDIUM
Local
|
Unspecified vulnerability in Oracle MySQL 5.6.28 and earlier and 5.7.10 and earlier allows local users to affect availability via vectors related to Security: Encryption.
|
NVD-CWE-noinfo
|
CVE-2016-0665
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:6.0:*
|
|
|
|
|
2024-11-21 11:42
2016-04-21
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1278
|
4.7
3.5
|
MEDIUM
Local
|
Unspecified vulnerability in Oracle MySQL 5.6.28 and earlier and 5.7.10 and earlier allows local users to affect availability via vectors related to Options.
|
NVD-CWE-noinfo
|
CVE-2016-0661
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:6.0:*
|
|
|
|
|
2024-11-21 11:42
2016-04-21
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1279
|
4.7
3.5
|
MEDIUM
Local
|
Unspecified vulnerability in Oracle MySQL 5.6.29 and earlier and 5.7.11 and earlier and MariaDB 10.0.x before 10.0.25 and 10.1.x before 10.1.14 allows local users to affect availability via vectors r…
|
NVD-CWE-noinfo
|
CVE-2016-0655
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:6.0:*
|
|
|
|
|
2024-11-21 11:42
2016-04-21
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1280
|
5.5
4.0
|
MEDIUM
Local
|
Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.48, 10.0.x before 10.0.24, and 10.1.x before 10.1.12 allows local users…
|
NVD-CWE-noinfo
|
CVE-2016-0650
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:6.0:*
|
|
|
|
|
2024-11-21 11:42
2016-04-21
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|