|
269161
|
9.8 |
CRITICAL
Network
|
qualcomm
|
mdm9206_firmware mdm9607_firmware mdm9650_firmware sd_210_firmware sd_212_firmware sd_205_firmware sd_835_firmware sda660_firmware
|
While generating trusted application id, An integer overflow can occur giving the trusted application an invalid identity in Snapdragon Mobile and Snapdragon Wear in versions MDM9206, MDM9607, MDM965…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2016-10502
|
2024-11-21 11:44 |
2018-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269162
|
9.8 |
CRITICAL
Network
|
projectsend
|
projectsend
|
ProjectSend (formerly cFTP) r582 allows Insecure Direct Object Reference via includes/actions.log.export.php.
|
CWE-285
Improper Authorization
|
CVE-2016-10734
|
2024-11-21 11:44 |
2018-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269163
|
9.8 |
CRITICAL
Network
|
projectsend
|
projectsend
|
ProjectSend (formerly cFTP) r582 allows directory traversal via file=../ in the process-zip-download.php query string.
|
CWE-22
Path Traversal
|
CVE-2016-10733
|
2024-11-21 11:44 |
2018-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269164
|
9.8 |
CRITICAL
Network
|
projectsend
|
projectsend
|
ProjectSend (formerly cFTP) r582 allows authentication bypass via a direct request for users.php, home.php, edit-file.php?file_id=1, or process-zip-download.php, or add_user_form_* parameters to user…
|
CWE-287
Improper Authentication
|
CVE-2016-10732
|
2024-11-21 11:44 |
2018-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269165
|
9.8 |
CRITICAL
Network
|
projectsend
|
projectsend
|
ProjectSend (formerly cFTP) r582 allows SQL injection via manage-files.php with the request parameter status, manage-files.php with the request parameter files, clients.php with the request parameter…
|
CWE-89
SQL Injection
|
CVE-2016-10731
|
2024-11-21 11:44 |
2018-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269166
|
7.8 |
HIGH
Local
|
zmanda redhat
|
amanda enterprise_linux
|
An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. Amstar is an Amanda Application API script. It should not be run by users direct…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-10730
|
2024-11-21 11:44 |
2018-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269167
|
7.8 |
HIGH
Local
|
zmanda redhat debian
|
amanda enterprise_linux debian_linux
|
An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. The "runtar" setuid root binary does not check for additional arguments supplied…
|
CWE-77
Command Injection
|
CVE-2016-10729
|
2024-11-21 11:44 |
2018-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269168
|
5.3 |
MEDIUM
Network
|
suricata-ids
|
suricata
|
An issue was discovered in Suricata before 3.1.2. If an ICMPv4 error packet is received as the first packet on a flow in the to_client direction, it confuses the rule grouping lookup logic. The tocli…
|
CWE-20
Improper Input Validation
|
CVE-2016-10728
|
2024-11-21 11:44 |
2018-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269169
|
9.8 |
CRITICAL
Network
|
canonical gnome
|
ubuntu_linux evolution
|
camel/providers/imapx/camel-imapx-server.c in the IMAPx component in GNOME evolution-data-server before 3.21.2 proceeds with cleartext data containing a password if the client wishes to use STARTTLS …
|
CWE-200
Information Exposure
|
CVE-2016-10727
|
2024-11-21 11:44 |
2018-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269170
|
7.5 |
HIGH
Network
|
duraspace
|
dspace
|
The XMLUI feature in DSpace before 3.6, 4.x before 4.5, and 5.x before 5.5 allows directory traversal via the themes/ path in an attack with two or more arbitrary characters and a colon before a path…
|
CWE-22
Path Traversal
|
CVE-2016-10726
|
2024-11-21 11:44 |
2018-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|