|
268771
|
9.8 |
CRITICAL
Network
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, the use of an out-of-range pointer offset is potentially possible in LTE.
|
CWE-476
NULL Pointer Dereference
|
CVE-2016-10344
|
2024-11-21 11:43 |
2017-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268772
|
9.8 |
CRITICAL
Network
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, sSL handshake failure with ClientHello rejection results in memory leak.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-10343
|
2024-11-21 11:43 |
2017-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268773
|
6.1 |
MEDIUM
Network
|
liferay
|
liferay_portal
|
XSS exists in Liferay Portal before 7.0 CE GA4 via a crafted redirect field to modules/apps/foundation/frontend-js/frontend-js-spa-web/src/main/resources/META-INF/resources/init.jsp.
|
CWE-79
Cross-site Scripting
|
CVE-2016-10404
|
2024-11-21 11:43 |
2017-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268774
|
7.5 |
HIGH
Network
|
sendio
|
sendio
|
Sendio versions before 8.2.1 were affected by a Local File Inclusion vulnerability that allowed an unauthenticated, remote attacker to read potentially sensitive system files via a specially crafted …
|
CWE-538
File and Directory Information Exposure
|
CVE-2016-10399
|
2024-11-21 11:43 |
2017-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268775
|
7.8 |
HIGH
Local
|
avira
|
antivirus
|
Avira Antivirus engine versions before 8.3.36.60 allow remote code execution as NT AUTHORITY\SYSTEM via a section header with a very large relative virtual address in a PE file, causing an integer ov…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-10402
|
2024-11-21 11:43 |
2017-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268776
|
8.8 |
HIGH
Network
|
zyxel
|
pk5001z_firmware
|
ZyXEL PK5001Z devices have zyad5001 as the su password, which makes it easier for remote attackers to obtain root access if a non-root account password is known (or a non-root default account exists …
|
CWE-255
Credentials Management
|
CVE-2016-10401
|
2024-11-21 11:43 |
2017-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268777
|
7.5 |
HIGH
Network
|
atutor
|
atutor
|
Directory Traversal exists in ATutor before 2.2.2 via the icon parameter to /mods/_core/courses/users/create_course.php. The attacker can read an arbitrary file by visiting get_course_icon.php?id= af…
|
CWE-22
Path Traversal
|
CVE-2016-10400
|
2024-11-21 11:43 |
2017-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268778
|
6.2 |
MEDIUM
Physics
|
google
|
android
|
Android 6.0 has an authentication bypass for attackers with root and physical access. Cryptographic authentication tokens (AuthTokens) used by the Trusted Execution Environment (TEE) are protected by…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-10398
|
2024-11-21 11:43 |
2017-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268779
|
7.5 |
HIGH
Network
|
php
|
php
|
In PHP before 5.6.28 and 7.x before 7.0.13, incorrect handling of various URI components in the URL parser could be used by attackers to bypass hostname-specific URL checks, as demonstrated by evil.e…
|
CWE-20
Improper Input Validation
|
CVE-2016-10397
|
2024-11-21 11:43 |
2017-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268780
|
7.5 |
HIGH
Network
|
ipsec-tools
|
ipsec-tools
|
The racoon daemon in IPsec-Tools 0.8.2 contains a remotely exploitable computational-complexity attack when parsing and storing ISAKMP fragments. The implementation permits a remote attacker to exhau…
|
CWE-407
Inefficient Algorithmic Complexity
|
CVE-2016-10396
|
2024-11-21 11:43 |
2017-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|