|
266441
|
9.8 |
CRITICAL
Network
|
citrix
|
xenserver
|
Citrix XenServer 7.0 before Hotfix XS70E003, when a deployment has been upgraded from an earlier release, might allow remote attackers on the management network to "compromise" a host by leveraging c…
|
CWE-284
Improper Access Control
|
CVE-2016-5302
|
2024-11-21 11:54 |
2016-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266442
|
9.8 |
CRITICAL
Network
|
nodepdf_project
|
nodepdf
|
Input passed to the Pdf() function is shell escaped and passed to child_process.exec() during PDF rendering. However, the shell escape does not properly encode all special characters, namely, semicol…
|
CWE-77
Command Injection
|
CVE-2016-4991
|
2024-11-21 11:53 |
2022-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266443
|
2.5 |
LOW
Local
|
ethz fedoraproject redhat
|
xquest fedora enterprise_linux
|
A password generation weakness exists in xquest through 2016-06-13.
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2016-4980
|
2024-11-21 11:53 |
2019-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266444
|
9.8 |
CRITICAL
Network
|
google
|
chrome
|
Unspecified vulnerabilities in Google Chrome before 54.0.2840.59.
|
NVD-CWE-noinfo
|
CVE-2016-5194
|
2024-11-21 11:53 |
2019-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266445
|
7.5 |
HIGH
Network
|
mozilla debian redhat suse avaya
|
nss debian_linux enterprise_linux linux_enterprise_server call_management_system breeze_platform iq aura_application_server_5300 aura_application_enablement_services aura_c…
|
A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote m…
|
CWE-476
NULL Pointer Dereference
|
CVE-2016-5285
|
2024-11-21 11:53 |
2019-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266446
|
3.3 |
LOW
Local
|
dovecot opensuse redhat
|
dovecot leap opensuse enterprise_linux
|
A postinstall script in the dovecot rpm allows local users to read the contents of newly created SSL/TLS key files.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2016-4983
|
2024-11-21 11:53 |
2019-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266447
|
9.1 |
CRITICAL
Network
|
google
|
chrome
|
browser/extensions/api/dial/dial_registry.cc in Google Chrome before 54.0.2840.98 on macOS, before 54.0.2840.99 on Windows, and before 54.0.2840.100 on Linux neglects to copy a device ID before an er…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2016-5202
|
2024-11-21 11:53 |
2019-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266448
|
5.4 |
MEDIUM
Network
|
f5
|
websafe_alert_server
|
Cross-Site-Scripting (XSS) vulnerabilities in F5 WebSafe Dashboard 3.9.5 and earlier, aka F5 WebSafe Alert Server, allow privileged authenticated users to inject arbitrary web script or HTML when cre…
|
CWE-79
Cross-site Scripting
|
CVE-2016-5236
|
2024-11-21 11:53 |
2019-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266449
|
6.1 |
MEDIUM
Network
|
f5
|
websafe_alert_server
|
A Cross Site Scripting (XSS) vulnerability in versions of F5 WebSafe Dashboard 3.9.x and earlier, aka F5 WebSafe Alert Server, allows an unauthenticated user to inject HTML via a crafted alert.
|
CWE-79
Cross-site Scripting
|
CVE-2016-5235
|
2024-11-21 11:53 |
2019-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266450
|
6.1 |
MEDIUM
Network
|
apache
|
http_server
|
Possible CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdir. This issue was mitigated by changes made in 2.4.25 and 2.2.32 which prohibit CR or LF injection into …
|
CWE-93
CRLF Injection
|
CVE-2016-4975
|
2024-11-21 11:53 |
2018-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|