|
266461
|
9.8 |
CRITICAL
Network
|
suse
|
yast2
|
yast2-users before 3.1.47, as used in SUSE Linux Enterprise 12 SP1, does not properly set empty password fields in /etc/shadow during an AutoYaST installation when the profile does not contain inst-s…
|
CWE-255
Credentials Management
|
CVE-2016-1601
|
2024-11-21 11:46 |
2016-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266462
|
5.4 |
MEDIUM
Network
|
novell
|
service_desk
|
Multiple cross-site scripting (XSS) vulnerabilities in Micro Focus Novell Service Desk before 7.2 allow remote authenticated users to inject arbitrary web script or HTML via a certain (1) user name, …
|
CWE-79
Cross-site Scripting
|
CVE-2016-1596
|
2024-11-21 11:46 |
2016-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266463
|
6.5 |
MEDIUM
Network
|
novell
|
service_desk
|
LiveTime/WebObjects/LiveTime.woa/wa/DownloadAction/downloadFile in Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to conduct Hibernate Query Language (HQL) injection att…
|
CWE-200
Information Exposure
|
CVE-2016-1595
|
2024-11-21 11:46 |
2016-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266464
|
6.5 |
MEDIUM
Network
|
novell
|
service_desk
|
Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to read arbitrary attachments via a request to a LiveTime.woa URL, as demonstrated by obtaining sensitive information via …
|
CWE-200
Information Exposure
|
CVE-2016-1594
|
2024-11-21 11:46 |
2016-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266465
|
7.2 |
HIGH
Network
|
novell
|
service_desk
|
Directory traversal vulnerability in the import users feature in Micro Focus Novell Service Desk before 7.2 allows remote authenticated administrators to upload and execute arbitrary JSP files via a …
|
CWE-22
Path Traversal
|
CVE-2016-1593
|
2024-11-21 11:46 |
2016-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266466
|
7.5 |
HIGH
Network
|
cisco
|
adaptive_security_appliance_software
|
The DHCPv6 relay implementation in Cisco Adaptive Security Appliance (ASA) Software 9.4.1 allows remote attackers to cause a denial of service (device reload) via crafted DHCPv6 packets, aka Bug ID C…
|
CWE-399
Resource Management Errors
|
CVE-2016-1367
|
2024-11-21 11:46 |
2016-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266467
|
7.5 |
HIGH
Network
|
cisco
|
wireless_lan_controller_software
|
Cisco Wireless LAN Controller (WLC) Software 7.4 before 7.4.130.0(MD) and 7.5, 7.6, and 8.0 before 8.0.110.0(ED) allows remote attackers to cause a denial of service (device reload) via crafted Bonjo…
|
CWE-20
Improper Input Validation
|
CVE-2016-1364
|
2024-11-21 11:46 |
2016-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266468
|
9.8 |
CRITICAL
Network
|
cisco
|
wireless_lan_controller_software
|
Buffer overflow in the redirection functionality in Cisco Wireless LAN Controller (WLC) Software 7.2 through 7.4 before 7.4.140.0(MD) and 7.5 through 8.0 before 8.0.115.0(ED) allows remote attackers …
|
CWE-399
Resource Management Errors
|
CVE-2016-1363
|
2024-11-21 11:46 |
2016-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266469
|
7.5 |
HIGH
Network
|
cisco
|
aireos
|
Cisco AireOS 4.1 through 7.4.120.0, 7.5.x, and 7.6.100.0 on Wireless LAN Controller (WLC) devices allows remote attackers to cause a denial of service (device reload) via a crafted HTTP request, aka …
|
CWE-399
Resource Management Errors
|
CVE-2016-1362
|
2024-11-21 11:46 |
2016-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266470
|
7.5 |
HIGH
Network
|
cisco
|
ios ios_xe
|
The NTP implementation in Cisco IOS 15.1 and 15.5 and IOS XE 3.2 through 3.17 allows remote attackers to modify the system time via crafted packets, aka Bug ID CSCux46898.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-1384
|
2024-11-21 11:46 |
2016-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|