Aggregator
CVE-2016-6253 | NetBSD up to 7.0.1 /usr/libexec/mail.local link following (NetBSD-SA2016-006 / EDB-40141)
1 month 1 week ago
A vulnerability categorized as problematic has been discovered in NetBSD up to 7.0.1. The impacted element is an unknown function in the library /usr/libexec/mail.local. Executing a manipulation can lead to link following.
This vulnerability is handled as CVE-2016-6253. It is possible to launch the attack on the local host. Additionally, an exploit exists.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2016-8213 | EMC Documentum Webtop/TaskSpace/Capital Projects 6.8 cross site scripting (ESA-2016-143 / BID-95625)
1 month 1 week ago
A vulnerability labeled as problematic has been found in EMC Documentum Webtop, TaskSpace and Capital Projects 6.8. Affected by this vulnerability is an unknown functionality. Such manipulation leads to cross site scripting.
This vulnerability is documented as CVE-2016-8213. The attack can be executed remotely. There is not any exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2016-5323 | LibTIFF up to 4.0.5 _TIFFFax3fillruns divide by zero (Nessus ID 93322 / ID 169468)
1 month 1 week ago
A vulnerability labeled as problematic has been found in LibTIFF up to 4.0.5. Affected by this issue is the function _TIFFFax3fillruns. Such manipulation leads to divide by zero.
This vulnerability is documented as CVE-2016-5323. The attack can be executed remotely. There is not any exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2016-9435 | w3m up to 0.5.3 dd Tag file.c HTMLtagproc1 input validation (Nessus ID 95650 / ID 169423)
1 month 1 week ago
A vulnerability marked as problematic has been reported in w3m up to 0.5.3. This affects the function HTMLtagproc1 of the file file.c of the component dd Tag Handler. Performing a manipulation results in improper input validation.
This vulnerability is reported as CVE-2016-9435. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2016-9436 | w3m up to 0.5.3 i Tag parsetagx.c input validation (Nessus ID 95650 / ID 169423)
1 month 1 week ago
A vulnerability described as problematic has been identified in w3m up to 0.5.3. This vulnerability affects unknown code of the file parsetagx.c of the component i Tag Handler. Executing a manipulation can lead to improper input validation.
This vulnerability appears as CVE-2016-9436. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is recommended.
vuldb.com
CVE-2017-5545 | libimobiledevice up to 1.12 Apple Property List Data plistutil.c main out-of-bounds (Nessus ID 96910 / ID 169744)
1 month 1 week ago
A vulnerability classified as critical has been found in libimobiledevice up to 1.12. This issue affects the function main of the file plistutil.c of the component Apple Property List Data Handler. The manipulation leads to out-of-bounds read.
This vulnerability is traded as CVE-2017-5545. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2016-10101 | Hitek Automize 10.x/11.x passManager.jsd inadequate encryption (BID-96840)
1 month 1 week ago
A vulnerability labeled as problematic has been found in Hitek Automize 10.x/11.x. The impacted element is an unknown function of the file passManager.jsd. The manipulation results in inadequate encryption strength.
This vulnerability is cataloged as CVE-2016-10101. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2016-10102 | Hitek Automize up to 10.25/11.14 Profile Password hitek.jar inadequate encryption (BID-96848)
1 month 1 week ago
A vulnerability marked as critical has been reported in Hitek Automize up to 10.25/11.14. This affects an unknown function of the file hitek.jar of the component Profile Password Handler. This manipulation causes inadequate encryption strength.
This vulnerability is registered as CVE-2016-10102. Remote exploitation of the attack is possible. No exploit is available.
vuldb.com
CVE-2016-10103 | Hitek Automize up to 10.25/11.14 GPG Encryption Profile encryptionProfiles.jsd inadequate encryption (BID-96850)
1 month 1 week ago
A vulnerability described as problematic has been identified in Hitek Automize up to 10.25/11.14. This impacts an unknown function of the file encryptionProfiles.jsd of the component GPG Encryption Profile Handler. Such manipulation leads to inadequate encryption strength.
This vulnerability is documented as CVE-2016-10103. The attack can be executed remotely. There is not any exploit available.
vuldb.com
CVE-2016-10104 | Hitek Automize up to 10.25/11.14 sshProfiles.jsd Password inadequate encryption (BID-96845)
1 month 1 week ago
A vulnerability classified as problematic has been found in Hitek Automize up to 10.25/11.14. Affected is an unknown function of the file sshProfiles.jsd. Performing a manipulation results in inadequate encryption strength (Password).
This vulnerability is reported as CVE-2016-10104. The attack is possible to be carried out remotely. No exploit exists.
vuldb.com
CVE-2016-10156 | systemd v228 Timer /src/basic/fs-util.c access control (EDB-41171 / Nessus ID 96793)
1 month 1 week ago
A vulnerability classified as critical was found in systemd v228. Affected by this vulnerability is an unknown functionality of the file /src/basic/fs-util.c of the component Timer Handler. Executing a manipulation can lead to improper access controls.
This vulnerability appears as CVE-2016-10156. The attack requires local access. In addition, an exploit is available.
Upgrading the affected component is advised.
vuldb.com
CVE-2016-10157 | Akamai NetSession 1.9.3.1 CSUNSAPI.dll code injection (ID 140366 / BID-95995)
1 month 1 week ago
A vulnerability, which was classified as critical, has been found in Akamai NetSession 1.9.3.1. Affected by this issue is some unknown functionality in the library CSUNSAPI.dll. The manipulation leads to code injection.
This vulnerability is traded as CVE-2016-10157. An attack has to be approached locally. There is no exploit available.
vuldb.com
Simple bypass of the link preview function in Outlook Junk folder, (Thu, May 14th)
1 month 1 week ago
Besides serving as a place where Microsoft Outlook places suspected spam, the Outlook Junk folder h
Ваш мозг уже разрушается от хронического недосыпа — есть способ это остановить
1 month 1 week ago
Ученые нашли способ не тупеть без сна. Правда, пока метод проверили только на грызунах.
18-Year-Old NGINX Rewrite Module Flaw Enables Unauthenticated RCE
1 month 1 week ago
Cybersecurity researchers have disclosed multiple security vulnerabilities impacting NGINX Plus and NGINX Open, including a critical flaw that remained undetected for 18 years.
The vulnerability, discovered by depthfirst, is a heap buffer overflow issue impacting ngx_http_rewrite_module (CVE-2026-42945, CVSS v4 score: 9.2) that could allow an attacker to achieve remote code execution or cause a
The Hacker News
18-Year-Old NGINX Rewrite Module Flaw Enables Unauthenticated RCE
1 month 1 week ago
Vulnerability / Web ServerCybersecurity researchers have disclosed multiple security vulnerabiliti
Critical MongoDB Vulnerability Allow Attackers to Execute Arbitrary Code
1 month 1 week ago
A newly disclosed critical vulnerability in MongoDB could allow threat actors to execute arbitrary code, potentially handing them complete control over affected servers and exposing millions of records to theft. The vulnerability, officially tracked as CVE-2026-8053, directly impacts MongoDB Server deployments. Arbitrary code execution is one of the most severe types of security flaws in […]
The post Critical MongoDB Vulnerability Allow Attackers to Execute Arbitrary Code appeared first on Cyber Security News.
Abinaya
CVE-2026-7912 | Google Chrome up to 147.0.7727.138 on Android GPU integer overflow (Nessus ID 314292 / WID-SEC-2026-1394)
1 month 1 week ago
A vulnerability was found in Google Chrome on Android. It has been declared as critical. This vulnerability affects unknown code of the component GPU. The manipulation results in integer overflow.
This vulnerability is cataloged as CVE-2026-7912. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-7913 | Google Chrome up to 147.0.7727.138 on Android DevTools Local Privilege Escalation (Nessus ID 314292 / WID-SEC-2026-1394)
1 month 1 week ago
A vulnerability was found in Google Chrome on Android. It has been classified as problematic. Impacted is an unknown function of the component DevTools. This manipulation causes Local Privilege Escalation.
This vulnerability is tracked as CVE-2026-7913. The attack is restricted to local execution. No exploit exists.
Upgrading the affected component is recommended.
vuldb.com