|
267611
|
5.9 |
MEDIUM
Network
|
isc debian canonical
|
dhcp debian_linux ubuntu_linux
|
ISC DHCP 4.1.x before 4.1-ESV-R13 and 4.2.x and 4.3.x before 4.3.4 does not restrict the number of concurrent TCP sessions, which allows remote attackers to cause a denial of service (INSIST assertio…
|
CWE-20
Improper Input Validation
|
CVE-2016-2774
|
2024-11-21 11:48 |
2016-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267612
|
5.3 |
MEDIUM
Network
|
google
|
chrome
|
The Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 49.0.2623.75, does not ignore a URL's path component in the case of a ServiceWorker fetch, which allows remo…
|
CWE-200
Information Exposure
|
CVE-2016-2845
|
2024-11-21 11:48 |
2016-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267613
|
8.8 |
HIGH
Network
|
google
|
chrome
|
WebKit/Source/core/layout/LayoutBlock.cpp in Blink, as used in Google Chrome before 49.0.2623.75, does not properly determine when anonymous block wrappers may exist, which allows remote attackers to…
|
CWE-20
Improper Input Validation
|
CVE-2016-2844
|
2024-11-21 11:48 |
2016-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267614
|
9.8 |
CRITICAL
Network
|
google
|
chrome v8
|
Multiple unspecified vulnerabilities in Google V8 before 4.9.385.26, as used in Google Chrome before 49.0.2623.75, allow attackers to cause a denial of service or possibly have other impact via unkno…
|
NVD-CWE-noinfo
|
CVE-2016-2843
|
2024-11-21 11:48 |
2016-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267615
|
5.3 |
MEDIUM
Network
|
moxa
|
ioadmin_firmware iologik_firmware
|
Moxa ioLogik E2200 devices before 3.12 and ioAdmin Configuration Utility before 3.18 do not properly encrypt data, which makes it easier for remote attackers to obtain the associated cleartext via un…
|
CWE-255
Credentials Management
|
CVE-2016-2283
|
2024-11-21 11:48 |
2016-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267616
|
5.3 |
MEDIUM
Network
|
moxa
|
ioadmin_firmware iologik_firmware
|
Moxa ioLogik E2200 devices before 3.12 and ioAdmin Configuration Utility before 3.18 do not properly encrypt credentials, which makes it easier for remote attackers to obtain the associated cleartext…
|
CWE-255
Credentials Management
|
CVE-2016-2282
|
2024-11-21 11:48 |
2016-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267617
|
5.9 |
MEDIUM
Network
|
hp
|
futuresmart_firmware
|
HP LaserJet printers and MFPs and OfficeJet Enterprise printers with firmware before 3.7.01 allow remote attackers to obtain sensitive information via unspecified vectors.
|
CWE-200
Information Exposure
|
CVE-2016-2244
|
2024-11-21 11:48 |
2016-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267618
|
7.9 |
HIGH
Local
|
hp
|
700_series_firmware 800_series_firmware z240_firmware z238_firmware zbook_firmware 1000_series_firmware elitebook_folio_1012_x2_g2
|
Sure Start on HP Commercial PCs 2015 allows local users to cause a denial of service (BIOS recovery failure) by leveraging administrative access.
|
CWE-284
Improper Access Control
|
CVE-2016-2243
|
2024-11-21 11:48 |
2016-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267619
|
9.8 |
CRITICAL
Network
|
openssl
|
openssl
|
The doapr_outch function in crypto/bio/b_print.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g does not verify that a certain memory allocation succeeds, which allows remote attackers to cau…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-2842
|
2024-11-21 11:48 |
2016-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267620
|
6.1 |
MEDIUM
Network
|
rockwellautomation
|
compactlogix_1769-l16er-bb1b_firmware compactlogix_1769-l18er-bb1b_firmware compactlogix_1769-l18erm-bb1b_firmware compactlogix_1769-l24er-qb1b_firmware compactlogix_1769-l24er-qbfc1b_fir…
|
Cross-site scripting (XSS) vulnerability in the web server in Rockwell Automation Allen-Bradley CompactLogix 1769-L* before 28.011+ allows remote attackers to inject arbitrary web script or HTML via …
|
CWE-79
Cross-site Scripting
|
CVE-2016-2279
|
2024-11-21 11:48 |
2016-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|