CVE List

Id CVE No. Status Description Phase Votes Comments Actions
96666  CVE-2016-9846  Candidate  QEMU (aka Quick Emulator) built with the Virtio GPU Device emulator support is vulnerable to a memory leakage issue. It could occur while updating the cursor data in update_cursor_data_virgl. A guest user/process could use this flaw to leak host memory bytes, resulting in DoS for a host.  Assigned (20161205)  None (candidate not yet proposed)    View
96667  CVE-2016-9847  Candidate  An issue was discovered in phpMyAdmin. When the user does not specify a blowfish_secret key for encrypting cookies, phpMyAdmin generates one at runtime. A vulnerability was reported where the way this value is created uses a weak algorithm. This could allow an attacker to determine the user"s blowfish_secret and potentially decrypt their cookies. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.  Assigned (20161206)  None (candidate not yet proposed)    View
96668  CVE-2016-9848  Candidate  An issue was discovered in phpMyAdmin. phpinfo (phpinfo.php) shows PHP information including values of HttpOnly cookies. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.  Assigned (20161206)  None (candidate not yet proposed)    View
96669  CVE-2016-9849  Candidate  An issue was discovered in phpMyAdmin. It is possible to bypass AllowRoot restriction ($cfg["Servers"][$i]["AllowRoot"]) and deny rules for username by using Null Byte in the username. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.  Assigned (20161206)  None (candidate not yet proposed)    View
96670  CVE-2016-9850  Candidate  An issue was discovered in phpMyAdmin. Username matching for the allow/deny rules may result in wrong matches and detection of the username in the rule due to non-constant execution time. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.  Assigned (20161206)  None (candidate not yet proposed)    View

Page 19334 of 20943, showing 5 records out of 104715 total, starting on record 96666, ending on 96670

Actions