|
267781
|
7.8 |
HIGH
Local
|
google linux
|
android linux_kernel
|
Heap-based buffer overflow in the wcnss_wlan_write function in drivers/net/wireless/wcnss/wcnss_wlan.c in the wcnss_wlan device driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center …
|
CWE-787
Out-of-bounds Write
|
CVE-2016-5342
|
2024-11-21 11:54 |
2016-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267782
|
6.1 |
MEDIUM
Network
|
zimbra
|
zimbra_collaboration_server
|
Multiple cross-site scripting (XSS) vulnerabilities in Zimbra Collaboration before 8.7.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2016-5721
|
2024-11-21 11:54 |
2016-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267783
|
7.8 |
HIGH
Local
|
readydesk
|
readydesk
|
ReadyDesk 9.1 allows local users to determine cleartext SQL Server credentials by reading the SQL_Config.aspx file and decrypting data with a hardcoded key in the ReadyDesk.dll file.
|
NVD-CWE-Other
|
CVE-2016-5683
|
2024-11-21 11:54 |
2016-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267784
|
4.3 |
MEDIUM
Network
|
accellion
|
kiteworks_appliance
|
Directory traversal vulnerability on Accellion Kiteworks appliances before kw2016.03.00 allows remote attackers to read files via a crafted URI.
|
CWE-22
Path Traversal
|
CVE-2016-5664
|
2024-11-21 11:54 |
2016-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267785
|
6.1 |
MEDIUM
Network
|
accellion
|
kiteworks_appliance
|
Multiple cross-site scripting (XSS) vulnerabilities in oauth_callback.php on Accellion Kiteworks appliances before kw2016.03.00 allow remote attackers to inject arbitrary web script or HTML via the (…
|
CWE-79
Cross-site Scripting
|
CVE-2016-5663
|
2024-11-21 11:54 |
2016-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267786
|
7.8 |
HIGH
Local
|
accellion
|
kiteworks_appliance
|
Accellion Kiteworks appliances before kw2016.03.00 use setuid-root permissions for /opt/bin/cli, which allows local users to gain privileges via unspecified vectors.
|
NVD-CWE-Other
|
CVE-2016-5662
|
2024-11-21 11:54 |
2016-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267787
|
8.8 |
HIGH
Network
|
redhat
|
cloudforms
|
The web UI in Red Hat CloudForms 4.1 allows remote authenticated users to execute arbitrary code via vectors involving "Lack of field filters."
|
CWE-284
Improper Access Control
|
CVE-2016-5383
|
2024-11-21 11:54 |
2016-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267788
|
7.5 |
HIGH
Network
|
ultravnc
|
repeater
|
UltraVNC Repeater before 1300 does not restrict destination IP addresses or TCP ports, which allows remote attackers to obtain open-proxy functionality by using a :: substring in between the IP addre…
|
CWE-284
Improper Access Control
|
CVE-2016-5673
|
2024-11-21 11:54 |
2016-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267789
|
9.8 |
CRITICAL
Network
|
dlink d-link
|
dir-868l_firmware dir-822_firmware dir-880l_firmware dir-850l_firmare dir-895l_firmware dir-817l\(w\)_firmware dir-818l\(w\)_firmware dir-890l_firmware dir-823_firmware dir…
|
Stack-based buffer overflow in dws/api/Login on D-Link DIR-850L B1 2.07 before 2.07WWB05, DIR-817 Ax, DIR-818LW Bx before 2.05b03beta03, DIR-822 C1 3.01 before 3.01WWb02, DIR-823 A1 1.00 before 1.00W…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-5681
|
2024-11-21 11:54 |
2016-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267790
|
7.5 |
HIGH
Network
|
zmodo
|
zp-ibh-13w zp-ne-14-s
|
ZModo ZP-NE14-S and ZP-IBH-13W devices do not enforce a WPA2 configuration setting, which allows remote attackers to trigger association with an arbitrary access point by using a recognized SSID valu…
|
CWE-284
Improper Access Control
|
CVE-2016-5650
|
2024-11-21 11:54 |
2016-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|