|
266921
|
8.8 |
HIGH
Network
|
sophos
|
cyberoam_cr25ing_utm_firmware
|
Sophos Cyberoam UTM CR25iNG 10.6.3 MR-5 allows remote authenticated users to bypass intended access restrictions via direct object reference, as demonstrated by a request for Licenseinformation.jsp. …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-7786
|
2024-11-21 11:58 |
2017-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266922
|
6.8 |
MEDIUM
Physics
|
apple
|
mac_os_x
|
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves mishandling of DMA in the "EFI" component. It allows physically proximate attackers to discover…
|
CWE-310
Cryptographic Issues
|
CVE-2016-7585
|
2024-11-21 11:58 |
2017-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266923
|
7.3 |
HIGH
Local
|
mcafee
|
anti-malware_scan_engine
|
Software Integrity Attacks vulnerability in Intel Security Anti-Virus Engine (AVE) 5200 through 5800 allows local attackers to bypass local security protection via a crafted input file.
|
CWE-284
Improper Access Control
|
CVE-2016-8032
|
2024-11-21 11:58 |
2017-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266924
|
4.9 |
MEDIUM
Network
|
fortinet
|
fortios
|
A read-only administrator on Fortinet devices with FortiOS 5.2.x before 5.2.10 GA and 5.4.x before 5.4.2 GA may have access to read-write administrators password hashes (not including super-admins) s…
|
CWE-200
Information Exposure
|
CVE-2016-7542
|
2024-11-21 11:58 |
2017-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266925
|
5.9 |
MEDIUM
Network
|
fortinet
|
fortios
|
Long lived sessions in Fortinet FortiGate devices with FortiOS 5.x before 5.4.0 could violate a security policy during IPS signature updates when the FortiGate's IPSengine is configured in flow mode.…
|
CWE-254
7PK - Security Features
|
CVE-2016-7541
|
2024-11-21 11:58 |
2017-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266926
|
7.3 |
HIGH
Local
|
mcafee
|
anti-malware_scan_engine
|
Software Integrity Attacks vulnerability in Intel Security Anti-Virus Engine (AVE) 5200 through 5800 allows local users to bypass local security protection via a crafted input file.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-8031
|
2024-11-21 11:58 |
2017-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266927
|
5.5 |
MEDIUM
Local
|
f5
|
big-ip_local_traffic_manager big-ip_application_acceleration_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_access_policy_manager big-ip_application_security_manager<…
|
In some cases the MCPD binary cache in F5 BIG-IP devices may allow a user with Advanced Shell access, or privileges to generate a qkview, to temporarily obtain normally unrecoverable information.
|
CWE-200
Information Exposure
|
CVE-2016-7474
|
2024-11-21 11:58 |
2017-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266928
|
7.5 |
HIGH
Network
|
clusterlabs suse opensuse_project opensuse redhat
|
pacemaker linux_enterprise_software_development_kit leap linux_enterprise_high_availability enterprise_linux_resilient_storage enterprise_linux_high_availability
|
Pacemaker before 1.1.15, when using pacemaker remote, might allow remote attackers to cause a denial of service (node disconnection) via an unauthenticated connection.
|
CWE-254
7PK - Security Features
|
CVE-2016-7797
|
2024-11-21 11:58 |
2017-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266929
|
5.9 |
MEDIUM
Network
|
f5
|
big-ip_local_traffic_manager big-ip_application_acceleration_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_access_policy_manager big-ip_application_security_manager<…
|
An unauthenticated remote attacker may be able to disrupt services on F5 BIG-IP 11.4.1 - 11.5.4 devices with maliciously crafted network traffic. This vulnerability affects virtual servers associated…
|
CWE-284
Improper Access Control
|
CVE-2016-7468
|
2024-11-21 11:58 |
2017-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266930
|
9.8 |
CRITICAL
Network
|
alienvault
|
ossim unified_security_management
|
The logcheck function in session.inc in AlienVault OSSIM before 5.3.1, when an action has been created, and USM before 5.3.1 allows remote attackers to bypass authentication and consequently obtain s…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-7955
|
2024-11-21 11:58 |
2017-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|