|
268311
|
7.5 |
HIGH
Network
|
cisco
|
web_security_appliance
|
Cisco AsyncOS 8.0 before 8.0.6-119 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (proxy-process hang) via a crafted HTTP POST request, aka Bug ID CSCuo1…
|
CWE-20
Improper Input Validation
|
CVE-2016-1380
|
2024-11-21 11:46 |
2016-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268312
|
6.1 |
MEDIUM
Network
|
wordpress
|
wordpress
|
Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/class-wp-theme.php in WordPress before 4.4.1 allow remote attackers to inject arbitrary web script or HTML via a (1) stylesheet name…
|
CWE-79
Cross-site Scripting
|
CVE-2016-1564
|
2024-11-21 11:46 |
2016-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268313
|
7.5 |
HIGH
Network
|
cisco
|
identity_services_engine_software
|
The Active Directory (AD) integration component in Cisco Identity Service Engine (ISE) before 1.2.0.899 patch 7, when AD group-membership authorization is enabled, allows remote attackers to cause a …
|
CWE-287 CWE-119
Improper Authentication Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-1402
|
2024-11-21 11:46 |
2016-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268314
|
6.1 |
MEDIUM
Network
|
cisco
|
unified_computing_system_central_software
|
Cross-site scripting (XSS) vulnerability in the management interface in Cisco Unified Computing System (UCS) Central Software 1.4(1a) allows remote attackers to inject arbitrary web script or HTML vi…
|
CWE-79
Cross-site Scripting
|
CVE-2016-1401
|
2024-11-21 11:46 |
2016-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268315
|
7.8 |
HIGH
Local
|
apple
|
itunes
|
Untrusted search path vulnerability in the installer in Apple iTunes before 12.4 allows local users to gain privileges via a Trojan horse DLL in the current working directory.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-1742
|
2024-11-21 11:46 |
2016-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268316
|
8.1 |
HIGH
Network
|
google
|
chrome
|
Google Chrome before 50.0.2661.102 on Android mishandles / (slash) and \ (backslash) characters, which allows attackers to conduct directory traversal attacks via a file: URL, related to net/base/esc…
|
CWE-22
Path Traversal
|
CVE-2016-1671
|
2024-11-21 11:46 |
2016-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268317
|
5.3 |
MEDIUM
Network
|
google opensuse debian
|
chrome opensuse debian_linux
|
Race condition in the ResourceDispatcherHostImpl::BeginRequest function in content/browser/loader/resource_dispatcher_host_impl.cc in Google Chrome before 50.0.2661.102 allows remote attackers to mak…
|
CWE-362
Race Condition
|
CVE-2016-1670
|
2024-11-21 11:46 |
2016-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268318
|
8.8 |
HIGH
Network
|
debian google opensuse nodejs canonical
|
debian_linux chrome opensuse v8 node.js ubuntu_linux
|
The Zone::New function in zone.cc in Google V8 before 5.0.71.47, as used in Google Chrome before 50.0.2661.102, does not properly determine when to expand certain memory allocations, which allows rem…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-1669
|
2024-11-21 11:46 |
2016-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268319
|
8.8 |
HIGH
Network
|
google opensuse debian
|
chrome opensuse debian_linux
|
The forEachForBinding function in WebKit/Source/bindings/core/v8/Iterable.h in the V8 bindings in Blink, as used in Google Chrome before 50.0.2661.102, uses an improper creation context, which allows…
|
CWE-284
Improper Access Control
|
CVE-2016-1668
|
2024-11-21 11:46 |
2016-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268320
|
8.8 |
HIGH
Network
|
opensuse debian google
|
opensuse debian_linux chrome
|
The TreeScope::adoptIfNeeded function in WebKit/Source/core/dom/TreeScope.cpp in the DOM implementation in Blink, as used in Google Chrome before 50.0.2661.102, does not prevent script execution duri…
|
CWE-284
Improper Access Control
|
CVE-2016-1667
|
2024-11-21 11:46 |
2016-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|