|
265291
|
8.8 |
HIGH
Network
|
apache
|
thrift
|
The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tool. Affected Apache Thrift 0.9.3 and older, Fixed in Apach…
|
CWE-77
Command Injection
|
CVE-2016-5397
|
2024-11-21 11:54 |
2018-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265292
|
7.0 |
HIGH
Local
|
google
|
android
|
Buffer overflow in the Qualcomm radio driver in Android before 2017-01-05 on Android One devices allows local users to gain privileges via a crafted application, aka Android internal bug 32639452 and…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-5345
|
2024-11-21 11:54 |
2018-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265293
|
9.8 |
CRITICAL
Network
|
puppet
|
puppet_agent
|
Versions of Puppet Agent prior to 1.6.0 included a version of the Puppet Execution Protocol (PXP) agent that passed environment variables through to Puppet runs. This could allow unauthorized code to…
|
CWE-94
Code Injection
|
CVE-2016-5713
|
2024-11-21 11:54 |
2017-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265294
|
7.2 |
HIGH
Network
|
puppet
|
puppet_enterprise puppet_agent
|
Puppet Enterprise 2015.3.3 and 2016.x before 2016.4.0, and Puppet Agent 1.3.6 through 1.7.0 allow remote attackers to bypass a host whitelist protection mechanism and execute arbitrary code on Puppet…
|
CWE-284
Improper Access Control
|
CVE-2016-5714
|
2024-11-21 11:54 |
2017-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265295
|
7.8 |
HIGH
Local
|
novell opensuse
|
suse_linux_enterprise_server suse_linux_enterprise_desktop leap
|
The mkdumprd script called "dracut" in the current working directory "." allows local users to trick the administrator into executing code as root.
|
CWE-20
Improper Input Validation
|
CVE-2016-5759
|
2024-11-21 11:54 |
2017-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265296
|
4.7 |
MEDIUM
Local
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, kernel stack data can be leaked to userspace by an audio driver.
|
CWE-200
Information Exposure
|
CVE-2016-5347
|
2024-11-21 11:54 |
2017-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265297
|
8.8 |
HIGH
Network
|
puppet
|
puppet_enterprise
|
The console in Puppet Enterprise 2015.x and 2016.x prior to 2016.4.0 includes unsafe string reads that potentially allows for remote code execution on the console node.
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2016-5716
|
2024-11-21 11:54 |
2017-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265298
|
6.1 |
MEDIUM
Network
|
apache
|
sling
|
In the XSS Protection API module before 1.0.12 in Apache Sling, the encoding done by the XSSAPI.encodeForJSString() method is not restrictive enough and for some input patterns allows script tags to …
|
CWE-79
Cross-site Scripting
|
CVE-2016-5394
|
2024-11-21 11:54 |
2017-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265299
|
7.5 |
HIGH
Network
|
freeipa
|
freeipa
|
FreeIPA 4.4.0 allows remote attackers to request an arbitrary SAN name for services.
|
CWE-284
Improper Access Control
|
CVE-2016-5414
|
2024-11-21 11:54 |
2017-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265300
|
7.5 |
HIGH
Network
|
libreswan fedoraproject
|
libreswan fedora
|
libreswan before 3.18 allows remote attackers to cause a denial of service (NULL pointer dereference and pluto daemon restart).
|
CWE-476
NULL Pointer Dereference
|
CVE-2016-5391
|
2024-11-21 11:54 |
2017-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|