Vulnerability index

Browse CVEs

322 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2019-17379 cPanel before 82.0.15 allows self stored XSS in the WHM SSL Storage Manager interface (SEC-527). Cpanel 78.0.39 / 82.0.15+ Fix from $1,6002019-10-09 MEDIUM 6.1 CVE-2019-17380 cPanel before 82.0.15 allows self XSS in the WHM Update Preferences interface (SEC-528). Cpanel 82.0.15+ Fix from $1,6002019-10-09 HIGH 8.8 CVE-2016-10811 In cPanel before 57.9999.54, /scripts/unsuspendacct exposed TTYs (SEC-116). Cpanel 11.50.6.2 / 11.52.6.1+ Fix from $1,9502019-08-07 HIGH 8.8 CVE-2016-10812 In cPanel before 57.9999.54, /scripts/enablefileprotect exposed TTYs (SEC-117). Cpanel 11.50.6.2 / 11.52.6.1+ Fix from $1,9502019-08-07 HIGH 8.8 CVE-2016-10801 cPanel before 58.0.4 has improper session handling for shared users (SEC-139). Cpanel 11.54.0.26 / 56.0.27+ Fix from $1,9502019-08-07 HIGH 8.8 CVE-2016-10802 cPanel before 58.0.4 allows code execution in the context of other user accounts through the PHP CGI handler (SEC-142). Cpanel 11.52.6.2 / 11.54.0.26+ Fix from $1,9502019-08-07 HIGH 8.8 CVE-2016-10805 cPanel before 57.9999.54 allows demo accounts to execute arbitrary code via ajax_maketext_syntax_util.pl (SEC-109). Cpanel 11.50.6.2 / 11.52.6.1+ Fix from $1,9502019-08-07 HIGH 8.8 CVE-2016-10808 In cPanel before 57.9999.54, /scripts/addpop and /scripts/delpop exposed TTYs (SEC-113). Cpanel 11.50.6.2 / 11.52.6.1+ Fix from $1,9502019-08-07 HIGH 8.8 CVE-2016-10809 In cPanel before 57.9999.54, /scripts/checkinfopages exposed a TTY to an unprivileged process (SEC-114). Cpanel 11.50.6.2 / 11.52.6.1+ Fix from $1,9502019-08-07 HIGH 8.8 CVE-2016-10810 In cPanel before 57.9999.54, /scripts/maildir_converter exposed a TTY to an unprivileged process (SEC-115). Cpanel 11.50.6.2 / 11.52.6.1+ Fix from $1,9502019-08-07 HIGH 8.1 CVE-2016-10804 The SQLite journal feature in cPanel before 57.9999.54 allows arbitrary file-overwrite operations during Horde Restore (SEC-58). Cpanel 11.50.6.2 / 11.52.6.1+ Fix from $1,9502019-08-07 HIGH 7.8 CVE-2016-10800 cPanel before 58.0.4 allows demo-mode escape via Site Templates and Boxtrapper API calls (SEC-138). Cpanel 56.0.27 / 58.0.4+ Fix from $1,9502019-08-07 HIGH 7.5 CVE-2016-10803 cPanel before 57.9999.105 allows newline injection via LOC records (CPANEL-6923). Cpanel 57.9999.105+ Fix from $1,9502019-08-07 MEDIUM 6.8 CVE-2016-10798 cPanel before 58.0.4 allows a file-ownership change (to nobody) via rearrangeacct (SEC-134). Cpanel 56.0.27 / 58.0.4+ Fix from $1,6002019-08-07 MEDIUM 6.5 CVE-2016-10807 cPanel before 57.9999.54 allows certain denial-of-service outcomes via /scripts/killpvhost (SEC-112). Cpanel 11.50.6.2 / 11.52.6.1+ Fix from $1,6002019-08-07 MEDIUM 5.5 CVE-2016-10799 cPanel before 58.0.4 does not set the Pear tmp directory during a PHP installation (SEC-137). Cpanel 11.52.6.2 / 11.54.0.26+ Fix from $1,6002019-08-07 MEDIUM 5.4 CVE-2016-10806 cPanel before 57.9999.54 allows self XSS on the Paper Lantern Landing Page (SEC-110). Cpanel 11.54.0.24 / 56.0.15+ Fix from $1,6002019-08-07 HIGH 8.8 CVE-2016-10792 cPanel before 59.9999.145 allows code execution in the context of other accounts via mailman list archives (SEC-141). Cpanel 11.52.6.6 / 11.54.0.29+ Fix from $1,9502019-08-06 HIGH 8.8 CVE-2016-10793 cPanel before 59.9999.145 allows arbitrary code execution due to an incorrect #! in Mail::SPF scripts (SEC-152). Cpanel 11.52.6.6 / 11.54.0.29+ Fix from $1,9502019-08-06 MEDIUM 6.5 CVE-2016-10794 cPanel before 59.9999.145 allows arbitrary file-read operations because of a multipart form processing error (SEC-154). Cpanel 11.52.6.6 / 11.54.0.29+ Fix from $1,6002019-08-06 MEDIUM 6.1 CVE-2016-10795 cPanel before 59.9999.145 allows stored XSS in the WHM tail_upcp2.cgi interface (SEC-156). Cpanel 11.52.6.6 / 11.54.0.29+ Fix from $1,6002019-08-06 MEDIUM 5.3 CVE-2016-10791 cPanel before 60.0.15 does not ensure that system accounts lack a valid password, so that logins are impossible (CPANEL-9559). Cpanel 60.0.15+ Fix from $1,6002019-08-06 HIGH 8.8 CVE-2016-10788 cPanel before 60.0.25 allows arbitrary code execution via Maketext in PostgreSQL adminbin (SEC-188). Cpanel 11.54.0.33 / 56.0.39+ Fix from $1,9502019-08-06 HIGH 8.8 CVE-2016-10789 cPanel before 60.0.25 allows code execution via the cpsrvd 403 error response handler (SEC-191). Cpanel 11.54.0.33 / 56.0.39+ Fix from $1,9502019-08-06 HIGH 7.5 CVE-2016-10790 cPanel before 60.0.25 does not use TLS for HTTP POSTs to listinput.cpanel.net (SEC-192). Cpanel 11.54.0.33 / 56.0.39+ Fix from $1,9502019-08-06 HIGH 8.1 CVE-2016-10787 The Host Access Control feature in cPanel before 60.0.25 mishandles actionless host.deny entries (SEC-187). Cpanel 11.54.0.33 / 56.0.39+ Fix from $1,9502019-08-06 MEDIUM 6.5 CVE-2016-10785 cPanel before 60.0.25 allows attackers to discover file contents during file copy operations (SEC-185). Cpanel 11.54.0.33 / 56.0.39+ Fix from $1,6002019-08-06 MEDIUM 6.5 CVE-2016-10786 cPanel before 60.0.25 allows members of the nobody group to read Apache HTTP Server SSL keys (SEC-186). Cpanel 11.54.0.33 / 56.0.39+ Fix from $1,6002019-08-06 MEDIUM 5.4 CVE-2016-10776 cPanel before 60.0.25 allows stored XSS during the homedir removal phase of WHM Account termination (SEC-174). Cpanel 11.54.0.33 / 56.0.39+ Fix from $1,6002019-08-06 MEDIUM 5.4 CVE-2016-10777 cPanel before 60.0.25 allows self XSS in WHM Tweak Settings for autodiscover_host (SEC-177). Cpanel 11.54.0.33 / 56.0.39+ Fix from $1,6002019-08-06