|
266301
|
7.5 |
HIGH
Network
|
cisco
|
prime_home
|
Cisco Prime Home 5.2.0 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML Externa…
|
CWE-611
XXE
|
CVE-2016-6408
|
2024-11-21 11:56 |
2016-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266302
|
7.8 |
HIGH
Local
|
cisco
|
ios
|
iox in Cisco IOS, possibly 15.6 and earlier, and IOS XE, possibly 3.18 and earlier, allows local users to execute arbitrary IOx Linux commands on the guest OS via crafted iox command-line options, ak…
|
CWE-78
OS Command
|
CVE-2016-6414
|
2024-11-21 11:56 |
2016-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266303
|
9.8 |
CRITICAL
Network
|
cisco
|
email_security_appliance_firmware
|
Cisco IronPort AsyncOS 9.1.2-023, 9.1.2-028, 9.1.2-036, 9.7.2-046, 9.7.2-047, 9.7.2-054, 10.0.0-124, and 10.0.0-125 on Email Security Appliance (ESA) devices, when Enrollment Client before 1.0.2-065 …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-6406
|
2024-11-21 11:56 |
2016-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266304
|
9.8 |
CRITICAL
Network
|
cisco
|
cloud_services_platform_2100
|
Cisco Cloud Services Platform (CSP) 2100 2.0 allows remote attackers to execute arbitrary code via a crafted dnslookup command in an HTTP request, aka Bug ID CSCuz89093.
|
CWE-20
Improper Input Validation
|
CVE-2016-6374
|
2024-11-21 11:56 |
2016-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266305
|
7.2 |
HIGH
Network
|
cisco
|
cloud_services_platform_2100
|
The web-based GUI in Cisco Cloud Services Platform (CSP) 2100 2.0 allows remote authenticated administrators to execute arbitrary OS commands as root via crafted platform commands, aka Bug ID CSCva00…
|
CWE-78
OS Command
|
CVE-2016-6373
|
2024-11-21 11:56 |
2016-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266306
|
6.5 |
MEDIUM
Network
|
huawei
|
ac6003_firmware ac6005_firmware ac6605_firmware acu2_firmware
|
Huawei AC6003, AC6005, AC6605, and ACU2 access controllers with software before V200R006C10SPC200 allows remote authenticated users to cause a denial of service (device restart) via crafted CAPWAP pa…
|
CWE-20
Improper Input Validation
|
CVE-2016-6824
|
2024-11-21 11:56 |
2016-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266307
|
7.5 |
HIGH
Network
|
huawei
|
usg2100_firmware usg2200_firmware usg5100_firmware usg5500_firmware
|
Buffer overflow in the Authentication, Authorization and Accounting (AAA) module in Huawei USG2100, USG2200, USG5100, and USG5500 unified security gateways with software before V300R001C10SPC600 allo…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-6669
|
2024-11-21 11:56 |
2016-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266308
|
9.8 |
CRITICAL
Network
|
debian artifex
|
debian_linux mupdf
|
Heap-based buffer overflow in the pdf_load_mesh_params function in pdf/pdf-shade.c in MuPDF allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a large decode a…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-6525
|
2024-11-21 11:56 |
2016-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266309
|
8.8 |
HIGH
Network
|
apache debian
|
jackrabbit debian_linux
|
Cross-site request forgery (CSRF) vulnerability in the CSRF content-type check in Jackrabbit-Webdav in Apache Jackrabbit 2.4.x before 2.4.6, 2.6.x before 2.6.6, 2.8.x before 2.8.3, 2.10.x before 2.10…
|
CWE-352
Origin Validation Error
|
CVE-2016-6801
|
2024-11-21 11:56 |
2016-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266310
|
9.8 |
CRITICAL
Network
|
dentsply_sirona
|
cdr_dicom
|
Dentsply Sirona (formerly Schick) CDR Dicom 5 and earlier has default passwords for the sa and cdr accounts, which allows remote attackers to obtain administrative access by leveraging knowledge of t…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2016-6530
|
2024-11-21 11:56 |
2016-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|