Vendorsnihncbi_toolboxany version
Vulnerabilities

nih NCBI ToolBox any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2018-16717
A heap-based buffer overflow exists in nph-viewgif.cgi in the 2.0.7 through 2.2.26 legacy versions of the NCBI ToolBox.
Published 2019-05-02 · Modified
9.8EPSS 0.016
CVE-2018-16716
A path traversal vulnerability exists in viewcgi.c in the 2.0.7 through 2.2.26 legacy versions of the NCBI ToolBox, which may result in reading of arbitrary files (i.e., significant information disclosure) or file deletion via the nph-viewgif.cgi query string.
Published 2019-05-02 · Modified
9.1EPSS 0.086
CVE-2018-16718
An XSS vulnerability exists in wwwblast.c in the 2.0.7 through 2.2.26 legacy versions of the NCBI ToolBox via a crafted -z1 argument.
Published 2019-05-02 · Modified
6.1EPSS 0.008