|
266301
|
9.8 |
CRITICAL
Network
|
jfrog
|
artifactory
|
JFrog Artifactory before 4.11 allows remote attackers to execute arbitrary code via an LDAP attribute with a crafted serialized Java object, aka LDAP entry poisoning.
|
CWE-20
Improper Input Validation
|
CVE-2016-6501
|
2024-11-21 11:56 |
2016-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266302
|
9.8 |
CRITICAL
Network
|
atlassian
|
crowd
|
The LDAP directory connector in Atlassian Crowd before 2.8.8 and 2.9.x before 2.9.5 allows remote attackers to execute arbitrary code via an LDAP attribute with a crafted serialized Java object, aka …
|
CWE-20
Improper Input Validation
|
CVE-2016-6496
|
2024-11-21 11:56 |
2016-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266303
|
9.8 |
CRITICAL
Network
|
barclamp-trove_project crowbar-openstack_project
|
barclamp-trove crowbar-openstack
|
The trove service user in (1) Openstack deployment (aka crowbar-openstack) and (2) Trove Barclamp (aka barclamp-trove and crowbar-barclamp-trove) in the Crowbar Framework has a default password, whic…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2016-6829
|
2024-11-21 11:56 |
2016-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266304
|
6.1 |
MEDIUM
Network
|
dotclear
|
dotclear
|
Multiple cross-site scripting (XSS) vulnerabilities in the media manager in Dotclear before 2.10 allow remote attackers to inject arbitrary web script or HTML via the (1) q or (2) link_type parameter…
|
CWE-79
Cross-site Scripting
|
CVE-2016-6523
|
2024-11-21 11:56 |
2016-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266305
|
8.8 |
HIGH
Network
|
google
|
android
|
A remote code execution vulnerability in Webview in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-11-05 could enable a remote attacker to execute arbitrary code when the user is…
|
CWE-74
Injection
|
CVE-2016-6754
|
2024-11-21 11:56 |
2016-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266306
|
5.5 |
MEDIUM
Local
|
google
|
android
|
An information disclosure vulnerability in kernel components, including the process-grouping subsystem and the networking subsystem, in Android before 2016-11-05 could enable a local malicious applic…
|
CWE-200
Information Exposure
|
CVE-2016-6753
|
2024-11-21 11:56 |
2016-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266307
|
5.5 |
MEDIUM
Local
|
google
|
android
|
An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver in Android before 2016-11-05 could enable a local m…
|
CWE-200
Information Exposure
|
CVE-2016-6752
|
2024-11-21 11:56 |
2016-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266308
|
5.5 |
MEDIUM
Local
|
google
|
android
|
An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver in Android before 2016-11-05 could enable a local m…
|
CWE-200
Information Exposure
|
CVE-2016-6751
|
2024-11-21 11:56 |
2016-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266309
|
5.5 |
MEDIUM
Local
|
google
|
android
|
An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver in Android before 2016-11-05 could enable a local m…
|
CWE-200
Information Exposure
|
CVE-2016-6750
|
2024-11-21 11:56 |
2016-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266310
|
5.5 |
MEDIUM
Local
|
google
|
android
|
An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver in Android before 2016-11-05 could enable a local m…
|
CWE-200
Information Exposure
|
CVE-2016-6749
|
2024-11-21 11:56 |
2016-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|