|
268341
|
10.0 |
CRITICAL
Network
|
cisco
|
information_server
|
The XML parser in Cisco Information Server (CIS) 6.2 allows remote attackers to read arbitrary files or cause a denial of service (CPU and memory consumption) via an external entity declaration in co…
|
NVD-CWE-Other
|
CVE-2016-1343
|
2024-11-21 11:46 |
2016-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268342
|
7.4 |
HIGH
Network
|
cisco
|
webex_meetings_server
|
Open redirect vulnerability in Cisco WebEx Meetings Server (CWMS) 2.6 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, aka Bug ID…
|
NVD-CWE-Other
|
CVE-2016-1389
|
2024-11-21 11:46 |
2016-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268343
|
7.5 |
HIGH
Network
|
cisco
|
application_policy_infrastructure_controller_enterprise_module
|
The API in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.0(1) allows remote attackers to spoof administrative notifications via crafted attribute-value pairs, aka B…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-1386
|
2024-11-21 11:46 |
2016-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268344
|
9.8 |
CRITICAL
Network
|
suse
|
yast2
|
yast2-users before 3.1.47, as used in SUSE Linux Enterprise 12 SP1, does not properly set empty password fields in /etc/shadow during an AutoYaST installation when the profile does not contain inst-s…
|
CWE-255
Credentials Management
|
CVE-2016-1601
|
2024-11-21 11:46 |
2016-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268345
|
5.4 |
MEDIUM
Network
|
novell
|
service_desk
|
Multiple cross-site scripting (XSS) vulnerabilities in Micro Focus Novell Service Desk before 7.2 allow remote authenticated users to inject arbitrary web script or HTML via a certain (1) user name, …
|
CWE-79
Cross-site Scripting
|
CVE-2016-1596
|
2024-11-21 11:46 |
2016-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268346
|
6.5 |
MEDIUM
Network
|
novell
|
service_desk
|
LiveTime/WebObjects/LiveTime.woa/wa/DownloadAction/downloadFile in Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to conduct Hibernate Query Language (HQL) injection att…
|
CWE-200
Information Exposure
|
CVE-2016-1595
|
2024-11-21 11:46 |
2016-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268347
|
6.5 |
MEDIUM
Network
|
novell
|
service_desk
|
Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to read arbitrary attachments via a request to a LiveTime.woa URL, as demonstrated by obtaining sensitive information via …
|
CWE-200
Information Exposure
|
CVE-2016-1594
|
2024-11-21 11:46 |
2016-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268348
|
7.2 |
HIGH
Network
|
novell
|
service_desk
|
Directory traversal vulnerability in the import users feature in Micro Focus Novell Service Desk before 7.2 allows remote authenticated administrators to upload and execute arbitrary JSP files via a …
|
CWE-22
Path Traversal
|
CVE-2016-1593
|
2024-11-21 11:46 |
2016-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268349
|
7.5 |
HIGH
Network
|
cisco
|
adaptive_security_appliance_software
|
The DHCPv6 relay implementation in Cisco Adaptive Security Appliance (ASA) Software 9.4.1 allows remote attackers to cause a denial of service (device reload) via crafted DHCPv6 packets, aka Bug ID C…
|
CWE-399
Resource Management Errors
|
CVE-2016-1367
|
2024-11-21 11:46 |
2016-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268350
|
7.5 |
HIGH
Network
|
cisco
|
wireless_lan_controller_software
|
Cisco Wireless LAN Controller (WLC) Software 7.4 before 7.4.130.0(MD) and 7.5, 7.6, and 8.0 before 8.0.110.0(ED) allows remote attackers to cause a denial of service (device reload) via crafted Bonjo…
|
CWE-20
Improper Input Validation
|
CVE-2016-1364
|
2024-11-21 11:46 |
2016-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|