|
266011
|
5.9 |
MEDIUM
Network
|
wireshark
|
wireshark
|
epan/dissectors/packet-qnet6.c in the QNX6 QNET dissector in Wireshark 2.x before 2.0.6 mishandles MAC address data, which allows remote attackers to cause a denial of service (out-of-bounds read and…
|
CWE-125
Out-of-bounds Read
|
CVE-2016-7175
|
2024-11-21 11:57 |
2016-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266012
|
9.8 |
CRITICAL
Network
|
huawei
|
uma
|
Huawei Unified Maintenance Audit (UMA) before V200R001C00SPC200 allows remote attackers to execute arbitrary commands via "special characters," a different vulnerability than CVE-2016-7109.
|
CWE-94
Code Injection
|
CVE-2016-7110
|
2024-11-21 11:57 |
2016-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266013
|
9.8 |
CRITICAL
Network
|
huawei
|
uma
|
Huawei Unified Maintenance Audit (UMA) before V200R001C00SPC200 allows remote attackers to execute arbitrary commands via "special characters," a different vulnerability than CVE-2016-7110.
|
CWE-94
Code Injection
|
CVE-2016-7109
|
2024-11-21 11:57 |
2016-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266014
|
6.5 |
MEDIUM
Network
|
huawei
|
uma
|
Huawei Unified Maintenance Audit (UMA) before V200R001C00SPC200 SPH206 allows remote authenticated users to obtain the MD5 hashes of arbitrary user passwords via unspecified vectors.
|
CWE-200
Information Exposure
|
CVE-2016-7108
|
2024-11-21 11:57 |
2016-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266015
|
7.5 |
HIGH
Network
|
huawei
|
uma
|
Huawei Unified Maintenance Audit (UMA) before V200R001C00SPC200 SPH206 allows remote attackers to reset arbitrary user passwords and consequently affect system data integrity via unspecified vectors.
|
CWE-284
Improper Access Control
|
CVE-2016-7107
|
2024-11-21 11:57 |
2016-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266016
|
6.6 |
MEDIUM
Local
|
huawei
|
e9000_chassis
|
XML external entity (XXE) vulnerability in the Hyper Management Module (HMM) in Huawei E9000 rack servers with software before V100R001C00SPC296 allows remote authenticated users to read arbitrary fi…
|
CWE-284
Improper Access Control
|
CVE-2016-6898
|
2024-11-21 11:57 |
2016-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266017
|
5.5 |
MEDIUM
Local
|
huawei
|
rh1288_v3_server_firmware rh2288_v3_server_firmware rh2288h_v3_server_firmware xh620_v3_server_firmware xh622_v3_server_firmware xh628_v3_server_firmware rh5885_v3_server_firmware
|
The Intelligent Baseboard Management Controller (iBMC) in Huawei RH1288 V3 servers with software before V100R003C00SPC613; RH2288 V3 servers with software before V100R003C00SPC617; RH2288H V3 servers…
|
CWE-399
Resource Management Errors
|
CVE-2016-6900
|
2024-11-21 11:57 |
2016-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266018
|
7.5 |
HIGH
Network
|
huawei
|
rh5885_v3_server_firmware rh1288_v3_server_firmware rh2288_v3_server_firmware rh2288h_v3_server_firmware xh620_v3_server_firmware xh622_v3_server_firmware xh628_v3_server_firmware
|
The Intelligent Baseboard Management Controller (iBMC) in Huawei RH1288 V3 servers with software before V100R003C00SPC613, RH2288 V3 servers with software before V100R003C00SPC617, RH2288H V3 servers…
|
CWE-310 CWE-200
Cryptographic Issues Information Exposure
|
CVE-2016-6899
|
2024-11-21 11:57 |
2016-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266019
|
7.5 |
HIGH
Network
|
f5
|
big-ip_local_traffic_manager big-ip_webaccelerator big-ip_application_acceleration_manager big-ip_global_traffic_manager big-ip_link_controller big-ip_advanced_firewall_manager big-…
|
The RESOLV::lookup iRule command in F5 BIG-IP LTM, APM, ASM, and Link Controller 10.2.1 through 10.2.4, 11.2.1, 11.4.x, 11.5.x before 11.5.4 HF2, 11.6.x before 11.6.1, and 12.0.0 before HF3; BIG-IP A…
|
CWE-399
Resource Management Errors
|
CVE-2016-6876
|
2024-11-21 11:57 |
2016-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266020
|
8.8 |
HIGH
Network
|
redhat
|
jboss_bpm_suite
|
The dashbuilder in Red Hat JBoss BPM Suite 6.3.2 does not properly handle CSRF tokens generated during an active session and includes them in query strings, which makes easier for remote attackers to…
|
CWE-352
Origin Validation Error
|
CVE-2016-7034
|
2024-11-21 11:57 |
2016-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|