|
265381
|
6.5 |
MEDIUM
Network
|
fortinet
|
fortiwan
|
The linkreport/tmp/admin_global page in Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote authenticated users to discover administrator cookies via a GET request.
|
CWE-200
Information Exposure
|
CVE-2016-4968
|
2024-11-21 11:53 |
2016-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265382
|
6.5 |
MEDIUM
Network
|
fortinet
|
fortiwan
|
Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote authenticated users to obtain sensitive information from (1) a backup of the device configuration via script/cfg_show.php or (2) PCA…
|
CWE-200
Information Exposure
|
CVE-2016-4967
|
2024-11-21 11:53 |
2016-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265383
|
6.5 |
MEDIUM
Network
|
fortinet
|
fortiwan
|
The diagnosis_control.php page in Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote authenticated users to download PCAP files via vectors related to the UserName GET parameter.
|
CWE-287
Improper Authentication
|
CVE-2016-4966
|
2024-11-21 11:53 |
2016-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265384
|
8.8 |
HIGH
Network
|
fortinet
|
fortiwan
|
Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote authenticated users with access to the nslookup functionality to execute arbitrary commands with root privileges via the graph param…
|
CWE-78
OS Command
|
CVE-2016-4965
|
2024-11-21 11:53 |
2016-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265385
|
7.5 |
HIGH
Network
|
redhat oracle libarchive
|
enterprise_linux_hpc_node enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation enterprise_linux_server_aus enterprise_linux_server_eus enterprise_linux_hpc_…
|
The archive_read_format_cpio_read_header function in archive_read_support_format_cpio.c in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) via a CPIO …
|
CWE-20
Improper Input Validation
|
CVE-2016-4809
|
2024-11-21 11:53 |
2016-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265386
|
7.3 |
HIGH
Network
|
yokogawa
|
stardom_fcn\/fcj
|
Yokogawa STARDOM FCN/FCJ controller R1.01 through R4.01 does not require authentication for Logic Designer connections, which allows remote attackers to reconfigure the device or cause a denial of se…
|
CWE-287
Improper Authentication
|
CVE-2016-4860
|
2024-11-21 11:53 |
2016-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265387
|
6.5 |
MEDIUM
Network
|
aki-null
|
yorufukurou
|
YoruFukurou (NightOwl) before 2.85 relies on support for emoji skin-tone modifiers even though this support is missing from the CoreText CTFramesetter API on OS X 10.9, which allows remote attackers …
|
CWE-20
Improper Input Validation
|
CVE-2016-4852
|
2024-11-21 11:53 |
2016-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265388
|
8.8 |
HIGH
Network
|
opensuse google
|
leap chrome
|
Multiple unspecified vulnerabilities in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux allow attackers to cause a denial of service or possibly have other impa…
|
NVD-CWE-noinfo
|
CVE-2016-5167
|
2024-11-21 11:53 |
2016-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265389
|
3.1 |
LOW
Network
|
google opensuse
|
chrome leap
|
The download implementation in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux does not properly restrict saving a file:// URL that is referenced by an http:// …
|
CWE-200
Information Exposure
|
CVE-2016-5166
|
2024-11-21 11:53 |
2016-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265390
|
6.1 |
MEDIUM
Network
|
google opensuse
|
chrome leap
|
Cross-site scripting (XSS) vulnerability in the Developer Tools (aka DevTools) subsystem in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux allows remote attack…
|
CWE-79
Cross-site Scripting
|
CVE-2016-5165
|
2024-11-21 11:53 |
2016-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|