|
267571
|
8.4 |
HIGH
Local
|
redhat
|
quickstart_cloud_installer
|
The kickstart file in Red Hat QuickStart Cloud Installer (QCI) forces use of MD5 passwords on deployed systems, which makes it easier for attackers to determine cleartext passwords via a brute-force …
|
CWE-254
7PK - Security Features
|
CVE-2016-6340
|
2024-11-21 11:55 |
2016-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267572
|
8.4 |
HIGH
Local
|
redhat
|
quickstart_cloud_installer
|
Red Hat QuickStart Cloud Installer (QCI) uses world-readable permissions for /etc/qci/answers, which allows local users to obtain the root password for the deployed system by reading the file.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-6322
|
2024-11-21 11:55 |
2016-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267573
|
5.5 |
MEDIUM
Local
|
artifex opensuse
|
mupdf leap opensuse
|
Use-after-free vulnerability in the pdf_load_xref function in pdf/pdf-xref.c in MuPDF allows remote attackers to cause a denial of service (crash) via a crafted PDF file.
|
CWE-416
Use After Free
|
CVE-2016-6265
|
2024-11-21 11:55 |
2016-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267574
|
9.8 |
CRITICAL
Network
|
debian westes
|
debian_linux flex
|
Heap-based buffer overflow in the yy_get_next_buffer function in Flex before 2.6.1 might allow context-dependent attackers to cause a denial of service or possibly execute arbitrary code via vectors …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-6354
|
2024-11-21 11:55 |
2016-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267575
|
8.6 |
HIGH
Network
|
oracle libarchive
|
linux libarchive
|
Integer overflow in the ISO9660 writer in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via vectors related to verifying f…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2016-6250
|
2024-11-21 11:55 |
2016-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267576
|
7.5 |
HIGH
Adjacent
|
huawei
|
ws331a_router_firmware
|
The management interface of Huawei WS331a routers with software before WS331a-10 V100R001C01B112 allows remote attackers to bypass authentication and obtain administrative access by sending "special …
|
CWE-287
Improper Authentication
|
CVE-2016-6159
|
2024-11-21 11:55 |
2016-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267577
|
6.1 |
MEDIUM
Network
|
huawei
|
ws331a_router_firmware
|
Multiple cross-site request forgery (CSRF) vulnerabilities in Huawei WS331a routers with software before WS331a-10 V100R001C01B112 allow remote attackers to hijack the authentication of administrator…
|
CWE-352
Origin Validation Error
|
CVE-2016-6158
|
2024-11-21 11:55 |
2016-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267578
|
6.5 |
MEDIUM
Network
|
libarchive redhat oracle
|
libarchive enterprise_linux_hpc_node enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation enterprise_linux_server_aus enterprise_linux_server_eus enterpr…
|
Integer overflow in the ISO parser in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) via a crafted ISO file.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2016-5844
|
2024-11-21 11:55 |
2016-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267579
|
8.6 |
HIGH
Local
|
rockwellautomation
|
rslogix_500_starter_edition rslogix_micro_starter_lite rslogix_micro_developer rslogix_500_standard_edition rslogix_500_professional_edition
|
Buffer overflow in Rockwell Automation RSLogix Micro Starter Lite, RSLogix Micro Developer, RSLogix 500 Starter Edition, RSLogix 500 Standard Edition, and RSLogix 500 Professional Edition allows remo…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-5814
|
2024-11-21 11:55 |
2016-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267580
|
9.4 |
CRITICAL
Network
|
otrs
|
faq
|
Multiple SQL injection vulnerabilities in the FAQ package 2.x before 2.3.6, 4.x before 4.0.5, and 5.x before 5.0.5 in Open Ticket Request System (OTRS) allow remote attackers to execute arbitrary SQL…
|
CWE-89
SQL Injection
|
CVE-2016-5843
|
2024-11-21 11:55 |
2016-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|