Vulnerabilities
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2016-10-27 | CVE-2016-1000122 | SQL Injection vulnerability in Huge-It Slider 1.0.9 XSS and SQLi in Huge IT Joomla Slider v1.0.9 extension | 7.2 |
2016-10-27 | CVE-2016-1000121 | Cross-site Scripting vulnerability in Huge-It Slider 1.0.9 XSS and SQLi in Huge IT Joomla Slider v1.0.9 extension | 4.8 |
2016-10-27 | CVE-2016-1000120 | SQL Injection vulnerability in Huge-It Catalog 1.0.4 SQLi and XSS in Huge IT catalog extension v1.0.4 for Joomla | 7.2 |
2016-10-27 | CVE-2016-5764 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Microfocus Rumba FTP Micro Focus Rumba FTP 4.X client buffer overflow makes it possible to corrupt the stack and allow arbitrary code execution. | 8.8 |
2016-10-27 | CVE-2016-1598 | Cross-site Scripting vulnerability in Novell products XSS in NetIQ IDM 4.5 Identity Applications before 4.5.4 allows attackers able to change their username to inject arbitrary HTML code into the Role Assignment administrator HTML pages. | 5.4 |
2016-10-27 | CVE-2016-1592 | Cross-site Scripting vulnerability in Netiq Identity Manager 4.5 XSS in NetIQ Designer for Identity Manager before 4.5.3 allows remote attackers to inject arbitrary HTML code via the nrfEntitlementReport.do CGI. | 6.1 |
2016-10-27 | CVE-2015-0787 | Cross-site Scripting vulnerability in Netiq Identity Manager 4.5 XSS in NetIQ Designer for Identity Manager before 4.5.3 allows remote attackers to inject arbitrary HTML code via the accessMgrDN value of the forgotUser.do CGI. | 6.1 |
2016-10-26 | CVE-2016-8506 | Cross-site Scripting vulnerability in Yandex Browser XSS in Yandex Browser Translator in Yandex browser for desktop for versions from 15.12 to 16.2 could be used by remote attacker for evaluation arbitrary javascript code. | 6.1 |
2016-10-26 | CVE-2016-8505 | Cross-site Scripting vulnerability in Yandex Yandex.Browser 16.4.0.94.4 XSS in Yandex Browser BookReader in Yandex browser for desktop for versions before 16.6. | 6.1 |
2016-10-26 | CVE-2016-8504 | Cross-Site Request Forgery (CSRF) vulnerability in Yandex Browser CSRF of synchronization form in Yandex Browser for desktop before version 16.6 could be used by remote attacker to steal saved data in browser profile. | 4.3 |