|
267011
|
5.5 |
MEDIUM
Local
|
symantec broadcom
|
protection_engine protection_for_sharepoint_servers mail_security_for_microsoft_exchange messaging_gateway mail_security_for_domino endpoint_protection endpoint_protection_for_small…
|
The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP); Symantec Email Security.Cloud; Symantec Data Center Security: Server; Symantec …
|
CWE-125
Out-of-bounds Read
|
CVE-2016-5309
|
2024-11-21 11:54 |
2017-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267012
|
8.8 |
HIGH
Network
|
symantec
|
web_gateway
|
Symantec Web Gateway (SWG) before 5.2.5 allows remote authenticated users to execute arbitrary OS commands.
|
CWE-78
OS Command
|
CVE-2016-5313
|
2024-11-21 11:54 |
2017-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267013
|
5.5 |
MEDIUM
Local
|
libtiff debian
|
libtiff debian_linux
|
The setByteArray function in tif_dir.c in libtiff 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tiff image.
|
CWE-125
Out-of-bounds Read
|
CVE-2016-5322
|
2024-11-21 11:54 |
2017-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267014
|
6.1 |
MEDIUM
Network
|
smartbear
|
swagger-ui
|
Swagger-UI before 2.2.1 has XSS via the Default field in the Definitions section.
|
CWE-79
Cross-site Scripting
|
CVE-2016-5682
|
2024-11-21 11:54 |
2017-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267015
|
5.4 |
MEDIUM
Network
|
opmantek
|
network_management_information_system
|
Opmantek NMIS before 8.5.12G has XSS via SNMP.
|
CWE-79
Cross-site Scripting
|
CVE-2016-5642
|
2024-11-21 11:54 |
2017-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267016
|
5.5 |
MEDIUM
Local
|
google
|
android
|
The high level operating systems (HLOS) was not providing sufficient memory address information to ensure that secure applications inside Qualcomm Secure Execution Environment (QSEE) only write to le…
|
CWE-200
Information Exposure
|
CVE-2016-5349
|
2024-11-21 11:54 |
2017-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267017
|
8.8 |
HIGH
Network
|
netiq
|
access_manager
|
A cross site request forgery protection mechanism in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 could be circumvented by repeated uploads causing a high load.
|
CWE-352
Origin Validation Error
|
CVE-2016-5758
|
2024-11-21 11:54 |
2017-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267018
|
9.8 |
CRITICAL
Network
|
netiq
|
access_manager
|
iManager Admin Console in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 was vulnerable to iFrame manipulation attacks, which could allow remote users to gain access to authenti…
|
CWE-200
Information Exposure
|
CVE-2016-5757
|
2024-11-21 11:54 |
2017-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267019
|
6.1 |
MEDIUM
Network
|
netiq
|
access_manager
|
Multiple components of the web tools in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 were vulnerable to Reflected Cross Site Scripting attacks which could be used to hijack us…
|
CWE-79
Cross-site Scripting
|
CVE-2016-5756
|
2024-11-21 11:54 |
2017-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267020
|
6.5 |
MEDIUM
Network
|
netiq
|
access_manager
|
NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 was vulnerable to clickjacking attacks due to a missing SAMEORIGIN filter in the "high encryption" setting.
|
CWE-20
Improper Input Validation
|
CVE-2016-5755
|
2024-11-21 11:54 |
2017-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|