|
268091
|
7.5 |
HIGH
Network
|
apache debian
|
xerces-c\+\+ debian_linux
|
Stack-based buffer overflow in Apache Xerces-C++ before 3.1.4 allows context-dependent attackers to cause a denial of service via a deeply nested DTD.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-4463
|
2024-11-21 11:52 |
2016-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268092
|
6.1 |
MEDIUM
Network
|
bosch
|
bladecontrol-webvis
|
Cross-site scripting (XSS) vulnerability in Rexroth Bosch BLADEcontrol-WebVIS 3.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2016-4508
|
2024-11-21 11:52 |
2016-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268093
|
6.4 |
MEDIUM
Network
|
bosch
|
bladecontrol-webvis
|
SQL injection vulnerability in Rexroth Bosch BLADEcontrol-WebVIS 3.0.2 and earlier allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2016-4507
|
2024-11-21 11:52 |
2016-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268094
|
5.3 |
MEDIUM
Network
|
apache
|
struts
|
The URLValidator class in Apache Struts 2 2.3.20 through 2.3.28.1 and 2.5.x before 2.5.1 allows remote attackers to cause a denial of service via a null value for a URL field.
|
CWE-20
Improper Input Validation
|
CVE-2016-4465
|
2024-11-21 11:52 |
2016-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268095
|
9.8 |
CRITICAL
Network
|
apache
|
struts
|
The REST plugin in Apache Struts 2 2.3.19 through 2.3.28.1 allows remote attackers to execute arbitrary code via a crafted expression.
|
CWE-20
Improper Input Validation
|
CVE-2016-4438
|
2024-11-21 11:52 |
2016-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268096
|
7.5 |
HIGH
Network
|
apache
|
struts
|
Apache Struts 2 2.3.20 through 2.3.28.1 allows remote attackers to bypass intended access restrictions and conduct redirection attacks via a crafted request.
|
CWE-20
Improper Input Validation
|
CVE-2016-4433
|
2024-11-21 11:52 |
2016-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268097
|
7.5 |
HIGH
Network
|
apache
|
struts
|
Apache Struts 2 2.3.20 through 2.3.28.1 allows remote attackers to bypass intended access restrictions and conduct redirection attacks by leveraging a default method.
|
CWE-20
Improper Input Validation
|
CVE-2016-4431
|
2024-11-21 11:52 |
2016-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268098
|
8.8 |
HIGH
Network
|
apache
|
struts
|
Apache Struts 2 2.3.20 through 2.3.28.1 mishandles token validation, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks via unspecified vectors.
|
CWE-352
Origin Validation Error
|
CVE-2016-4430
|
2024-11-21 11:52 |
2016-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268099
|
7.3 |
HIGH
Network
|
eaton
|
elcsoft
|
Stack-based buffer overflow in ELCSimulator in Eaton ELCSoft 2.4.01 and earlier allows remote attackers to execute arbitrary code via a long packet.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-4512
|
2024-11-21 11:52 |
2016-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268100
|
6.0 |
MEDIUM
Network
|
eaton
|
elcsoft
|
Heap-based buffer overflow in elcsoft.exe in Eaton ELCSoft 2.4.01 and earlier allows remote authenticated users to execute arbitrary code via a crafted file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-4509
|
2024-11-21 11:52 |
2016-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|