|
266351
|
8.8 |
HIGH
Network
|
cisco
|
prime_infrastructure evolved_programmable_network_manager
|
Cisco Prime Infrastructure 1.2 through 3.1 and Evolved Programmable Network Manager (EPNM) 1.2 and 2.0 allow remote authenticated users to execute arbitrary commands or upload files via a crafted HTT…
|
CWE-20
Improper Input Validation
|
CVE-2016-1408
|
2024-11-21 11:46 |
2016-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266352
|
9.8 |
CRITICAL
Network
|
cisco
|
prime_infrastructure evolved_programmable_network_manager
|
The API in Cisco Prime Infrastructure 1.2 through 3.0 and Evolved Programmable Network Manager (EPNM) 1.2 allows remote attackers to execute arbitrary code or obtain sensitive management information …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-1289
|
2024-11-21 11:46 |
2016-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266353
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
nfsd in the Linux kernel through 4.6.3 allows local users to bypass intended file-permission restrictions by setting a POSIX ACL, related to nfs2acl.c, nfs3acl.c, and nfs4acl.c.
|
CWE-284
Improper Access Control
|
CVE-2016-1237
|
2024-11-21 11:46 |
2016-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266354
|
7.8 |
HIGH
Local
|
linux novell canonical debian
|
linux_kernel suse_linux_enterprise_server suse_linux_enterprise_live_patching suse_linux_enterprise_desktop suse_linux_enterprise_module_for_public_cloud suse_linux_enterprise_workstat…
|
The ecryptfs_privileged_open function in fs/ecryptfs/kthread.c in the Linux kernel before 4.6.3 allows local users to gain privileges or cause a denial of service (stack memory consumption) via vecto…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-1583
|
2024-11-21 11:46 |
2016-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266355
|
6.1 |
MEDIUM
Network
|
cisco
|
unified_contact_center_enterprise
|
Cross-site scripting (XSS) vulnerability in the management interface in Cisco Unified Contact Center Enterprise through 10.5(2) allows remote attackers to inject arbitrary web script or HTML via a cr…
|
CWE-79
Cross-site Scripting
|
CVE-2016-1439
|
2024-11-21 11:46 |
2016-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266356
|
7.5 |
HIGH
Network
|
cisco
|
asyncos
|
Cisco AsyncOS 9.7.0-125 on Email Security Appliance (ESA) devices allows remote attackers to bypass intended spam filtering via crafted executable content in a ZIP archive, aka Bug ID CSCuy39210.
|
CWE-20 CWE-254
Improper Input Validation 7PK - Security Features
|
CVE-2016-1438
|
2024-11-21 11:46 |
2016-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266357
|
6.5 |
MEDIUM
Network
|
cisco
|
prime_collaboration_deployment
|
SQL injection vulnerability in the SQL database in Cisco Prime Collaboration Deployment before 11.5.1 allows remote authenticated users to execute arbitrary SQL commands via a crafted URL, aka Bug ID…
|
CWE-89
SQL Injection
|
CVE-2016-1437
|
2024-11-21 11:46 |
2016-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266358
|
7.5 |
HIGH
Network
|
cisco
|
asr_5000_software
|
The General Packet Radio Switching Tunneling Protocol 1 (aka GTPv1) implementation on Cisco ASR 5000 Packet Data Network Gateway devices before 19.4 allows remote attackers to cause a denial of servi…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-1436
|
2024-11-21 11:46 |
2016-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266359
|
7.0 |
HIGH
Local
|
cisco
|
ip_phone_8800_series_firmware
|
Cisco 8800 phones with software 11.0(1) do not properly enforce mounted-filesystem permissions, which allows local users to write to arbitrary files by leveraging shell access, aka Bug ID CSCuz03014.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-1435
|
2024-11-21 11:46 |
2016-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266360
|
6.5 |
MEDIUM
Network
|
cisco
|
ip_phone_8800_series_firmware
|
The license-certificate upload functionality on Cisco 8800 phones with software 11.0(1) allows remote authenticated users to delete arbitrary files via an invalid file, aka Bug ID CSCuz03010.
|
CWE-22 CWE-20
Path Traversal Improper Input Validation
|
CVE-2016-1434
|
2024-11-21 11:46 |
2016-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|