|
267981
|
9.8 |
CRITICAL
Network
|
aver
|
eh6108h\+_firmware
|
AVer Information EH6108H+ devices with firmware X9.03.24.00.07l have hardcoded accounts, which allows remote attackers to obtain root access by leveraging knowledge of the credentials and establishin…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2016-6535
|
2024-11-21 11:56 |
2016-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267982
|
6.5 |
MEDIUM
Network
|
cisco
|
fog_director
|
Cisco Fog Director 1.0(0) for IOx allows remote authenticated users to bypass intended access restrictions and write to arbitrary files via the Cartridge interface, aka Bug ID CSCuz89368.
|
CWE-20
Improper Input Validation
|
CVE-2016-6405
|
2024-11-21 11:56 |
2016-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267983
|
6.1 |
MEDIUM
Network
|
cisco
|
ios
|
Cross-site scripting (XSS) vulnerability in the web framework in Cisco IOx Local Manager in IOS 15.5(2)T and IOS XE allows remote attackers to inject arbitrary web script or HTML via a crafted URL, a…
|
CWE-79
Cross-site Scripting
|
CVE-2016-6404
|
2024-11-21 11:56 |
2016-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267984
|
5.9 |
MEDIUM
Network
|
cisco
|
ios
|
The Data in Motion (DMo) application in Cisco IOS 15.6(1)T and IOS XE, when the IOx feature set is enabled, allows remote attackers to cause a denial of service via a crafted packet, aka Bug IDs CSCu…
|
CWE-399
Resource Management Errors
|
CVE-2016-6403
|
2024-11-21 11:56 |
2016-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267985
|
7.8 |
HIGH
Local
|
cisco
|
unified_computing_system
|
UCS Manager and UCS 6200 Fabric Interconnects in Cisco Unified Computing System (UCS) through 3.0(2d) allow local users to obtain OS root access via crafted CLI input, aka Bug ID CSCuz91263.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-6402
|
2024-11-21 11:56 |
2016-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267986
|
6.1 |
MEDIUM
Network
|
emc
|
vipr_srm
|
Cross-site scripting (XSS) vulnerability in EMC ViPR SRM before 3.7.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2016-6643
|
2024-11-21 11:56 |
2016-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267987
|
6.1 |
MEDIUM
Network
|
emc
|
vipr_srm
|
Cross-site request forgery (CSRF) vulnerability in EMC ViPR SRM before 3.7.2 allows remote attackers to hijack the authentication of administrators for requests that upload files.
|
CWE-352
Origin Validation Error
|
CVE-2016-6642
|
2024-11-21 11:56 |
2016-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267988
|
7.6 |
HIGH
Network
|
emc
|
vipr_srm
|
Cross-site scripting (XSS) vulnerability in EMC ViPR SRM before 3.7.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2016-6641
|
2024-11-21 11:56 |
2016-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267989
|
7.5 |
HIGH
Network
|
cloudfoundry pivotal
|
php-buildpack cloud_foundry_elastic_runtime
|
Cloud Foundry PHP Buildpack (aka php-buildpack) before 4.3.18 and PHP Buildpack Cf-release before 242, as used in Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.38 and 1.7.x before 1.7.19 and…
|
CWE-254
7PK - Security Features
|
CVE-2016-6639
|
2024-11-21 11:56 |
2016-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267990
|
5.3 |
MEDIUM
Network
|
emc
|
documentum_d2
|
EMC Documentum D2 4.5 before patch 15 and 4.6 before patch 03 allows remote attackers to read arbitrary Docbase documents by leveraging knowledge of an r_object_id value.
|
CWE-264 CWE-200
Permissions, Privileges, and Access Controls Information Exposure
|
CVE-2016-6644
|
2024-11-21 11:56 |
2016-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|