Vulnerability index

Browse CVEs

156 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2016-9859 An issue was discovered in phpMyAdmin. With a crafted request parameter value it is possible to initiate a denial of service attack in import feature… phpMyAdmin Patch available Fix from $1,6002016-12-11 MEDIUM 5.3 CVE-2016-9858 An issue was discovered in phpMyAdmin. With a crafted request parameter value it is possible to initiate a denial of service attack in saved searches… phpMyAdmin Patch available Fix from $1,6002016-12-11 MEDIUM 6.1 CVE-2016-9857 An issue was discovered in phpMyAdmin. XSS is possible because of a weakness in a regular expression used in some JavaScript processing. All 4.6.x ve… phpMyAdmin Patch available Fix from $1,6002016-12-11 MEDIUM 6.1 CVE-2016-9856 An XSS issue was discovered in phpMyAdmin because of an improper fix for CVE-2016-2559 in PMASA-2016-10. This issue is resolved by using a copy of a … phpMyAdmin Patch available Fix from $1,6002016-12-11 MEDIUM 5.3 CVE-2016-9855 An issue was discovered in phpMyAdmin. By calling some scripts that are part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin… phpMyAdmin Patch available Fix from $1,6002016-12-11 MEDIUM 5.3 CVE-2016-9854 An issue was discovered in phpMyAdmin. By calling some scripts that are part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin… phpMyAdmin Patch available Fix from $1,6002016-12-11 MEDIUM 5.3 CVE-2016-9853 An issue was discovered in phpMyAdmin. By calling some scripts that are part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin… phpMyAdmin Patch available Fix from $1,6002016-12-11 MEDIUM 5.3 CVE-2016-9852 An issue was discovered in phpMyAdmin. By calling some scripts that are part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin… phpMyAdmin Patch available Fix from $1,6002016-12-11 MEDIUM 5.3 CVE-2016-9851 An issue was discovered in phpMyAdmin. With a crafted request parameter value it is possible to bypass the logout timeout. All 4.6.x versions (prior … phpMyAdmin Patch available Fix from $1,6002016-12-11 MEDIUM 5.3 CVE-2016-9850 An issue was discovered in phpMyAdmin. Username matching for the allow/deny rules may result in wrong matches and detection of the username in the ru… phpMyAdmin Patch available Fix from $1,6002016-12-11 CRITICAL 9.8 CVE-2016-9849 An issue was discovered in phpMyAdmin. It is possible to bypass AllowRoot restriction ($cfg['Servers'][$i]['AllowRoot']) and deny rules for username … phpMyAdmin Patch available Fix from $2,3002016-12-11 MEDIUM 5.3 CVE-2016-9848 An issue was discovered in phpMyAdmin. phpinfo (phpinfo.php) shows PHP information including values of HttpOnly cookies. All 4.6.x versions (prior to… phpMyAdmin Patch available Fix from $1,6002016-12-11 MEDIUM 5.3 CVE-2016-9847 An issue was discovered in phpMyAdmin. When the user does not specify a blowfish_secret key for encrypting cookies, phpMyAdmin generates one at runti… phpMyAdmin Patch available Fix from $1,6002016-12-11 HIGH 8.1 CVE-2016-6633 An issue was discovered in phpMyAdmin. phpMyAdmin can be used to trigger a remote code execution attack against certain PHP installations that are ru… phpMyAdmin Patch available Fix from $1,9502016-12-11 MEDIUM 5.9 CVE-2016-6632 An issue was discovered in phpMyAdmin where, under certain conditions, phpMyAdmin may not delete temporary files during the import of ESRI files. All… phpMyAdmin Patch available Fix from $1,6002016-12-11 HIGH 7.5 CVE-2016-6631 An issue was discovered in phpMyAdmin. A user can execute a remote code execution attack against a server when phpMyAdmin is being run as a CGI appli… phpMyAdmin Patch available Fix from $1,9502016-12-11 MEDIUM 6.5 CVE-2016-6630 An issue was discovered in phpMyAdmin. An authenticated user can trigger a denial-of-service (DoS) attack by entering a very long password at the cha… phpMyAdmin Patch available Fix from $1,6002016-12-11 CRITICAL 9.8 CVE-2016-6629 An issue was discovered in phpMyAdmin involving the $cfg['ArbitraryServerRegexp'] configuration directive. An attacker could reuse certain cookie val… phpMyAdmin Patch available Fix from $2,3002016-12-11 MEDIUM 6.3 CVE-2016-6628 An issue was discovered in phpMyAdmin. An attacker may be able to trigger a user to download a specially crafted malicious SVG file. All 4.6.x versio… phpMyAdmin Patch available Fix from $1,6002016-12-11 MEDIUM 5.3 CVE-2016-6627 An issue was discovered in phpMyAdmin. An attacker can determine the phpMyAdmin host location through the file url.php. All 4.6.x versions (prior to … phpMyAdmin Patch available Fix from $1,6002016-12-11 MEDIUM 5.4 CVE-2016-6626 An issue was discovered in phpMyAdmin. An attacker could redirect a user to a malicious web page. All 4.6.x versions (prior to 4.6.4), 4.4.x versions… phpMyAdmin Patch available Fix from $1,6002016-12-11 MEDIUM 5.9 CVE-2016-6624 An issue was discovered in phpMyAdmin involving improper enforcement of the IP-based authentication rules. When phpMyAdmin is used with IPv6 in a pro… phpMyAdmin Patch available Fix from $1,6002016-12-11 MEDIUM 6.5 CVE-2016-6623 An issue was discovered in phpMyAdmin. An authorized user can cause a denial-of-service (DoS) attack on a server by passing large values to a loop. A… phpMyAdmin Patch available Fix from $1,6002016-12-11 MEDIUM 5.9 CVE-2016-6622 An issue was discovered in phpMyAdmin. An unauthenticated user is able to execute a denial-of-service (DoS) attack by forcing persistent connections … phpMyAdmin Patch available Fix from $1,6002016-12-11 CRITICAL 9.8 CVE-2016-6620 An issue was discovered in phpMyAdmin. Some data is passed to the PHP unserialize() function without verification that it's valid serialized data. Th… phpMyAdmin Patch available Fix from $2,3002016-12-11 HIGH 8.8 CVE-2016-6619 An issue was discovered in phpMyAdmin. In the user interface preference feature, a user can execute an SQL injection attack against the account of th… phpMyAdmin Patch available Fix from $1,9502016-12-11 MEDIUM 6.5 CVE-2016-6618 An issue was discovered in phpMyAdmin. The transformation feature allows a user to trigger a denial-of-service (DoS) attack against the server. All 4… phpMyAdmin Patch available Fix from $1,6002016-12-11 HIGH 8.1 CVE-2016-6617 An issue was discovered in phpMyAdmin. A specially crafted database and/or table name can be used to trigger an SQL injection attack through the expo… phpMyAdmin Patch available Fix from $1,9502016-12-11 HIGH 7.5 CVE-2016-6616 An issue was discovered in phpMyAdmin. In the "User group" and "Designer" features, a user can execute an SQL injection attack against the account of… phpMyAdmin Patch available Fix from $1,9502016-12-11 MEDIUM 6.1 CVE-2016-6615 XSS issues were discovered in phpMyAdmin. This affects navigation pane and database/table hiding feature (a specially-crafted database name can be us… phpMyAdmin Patch available Fix from $1,6002016-12-11