|
268441
|
7.5 |
HIGH
Network
|
osram
|
lightify_pro
|
OSRAM SYLVANIA Osram Lightify Pro through 2016-07-26 allows Zigbee replay.
|
CWE-284
Improper Access Control
|
CVE-2016-5058
|
2024-11-21 11:53 |
2017-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268442
|
7.5 |
HIGH
Network
|
osram
|
lightify_pro
|
OSRAM SYLVANIA Osram Lightify Pro through 2016-07-26 does not use SSL pinning.
|
CWE-254
7PK - Security Features
|
CVE-2016-5057
|
2024-11-21 11:53 |
2017-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268443
|
7.5 |
HIGH
Network
|
osram
|
lightify_pro
|
OSRAM SYLVANIA Osram Lightify Pro before 2016-07-26 uses only 8 hex digits for a PSK.
|
CWE-326
Inadequate Encryption Strength
|
CVE-2016-5056
|
2024-11-21 11:53 |
2017-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268444
|
6.1 |
MEDIUM
Network
|
osram
|
lightify_pro
|
OSRAM SYLVANIA Osram Lightify Pro before 2016-07-26 has XSS in the username field and Wireless Client Mode configuration page.
|
CWE-79
Cross-site Scripting
|
CVE-2016-5055
|
2024-11-21 11:53 |
2017-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268445
|
7.5 |
HIGH
Network
|
osram
|
lightify_home
|
OSRAM SYLVANIA Osram Lightify Home through 2016-07-26 allows Zigbee replay.
|
CWE-284
Improper Access Control
|
CVE-2016-5054
|
2024-11-21 11:53 |
2017-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268446
|
9.8 |
CRITICAL
Network
|
osram
|
lightify_home
|
OSRAM SYLVANIA Osram Lightify Home before 2016-07-26 allows remote attackers to execute arbitrary commands via TCP port 4000.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2016-5053
|
2024-11-21 11:53 |
2017-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268447
|
7.5 |
HIGH
Network
|
osram
|
lightify_home
|
OSRAM SYLVANIA Osram Lightify Home through 2016-07-26 does not use SSL pinning.
|
CWE-254
7PK - Security Features
|
CVE-2016-5052
|
2024-11-21 11:53 |
2017-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268448
|
7.5 |
HIGH
Network
|
osram
|
lightify_home
|
OSRAM SYLVANIA Osram Lightify Home before 2016-07-26 stores a PSK in cleartext under /private/var/mobile/Containers/Data/Application.
|
CWE-200
Information Exposure
|
CVE-2016-5051
|
2024-11-21 11:53 |
2017-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268449
|
5.5 |
MEDIUM
Local
|
apache
|
ambari
|
Apache Ambari 2.x before 2.4.0 includes KDC administrator passwords on the kadmin command line, which allows local users to obtain sensitive information via a process listing.
|
CWE-200
Information Exposure
|
CVE-2016-4976
|
2024-11-21 11:53 |
2017-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268450
|
7.5 |
HIGH
Network
|
openslp
|
openslp
|
The _xrealloc function in xlsp_xmalloc.c in OpenSLP 2.0.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a large number of crafted packets, which trigge…
|
CWE-476
NULL Pointer Dereference
|
CVE-2016-4912
|
2024-11-21 11:53 |
2017-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|