|
266481
|
9.8 |
CRITICAL
Network
|
netgear
|
wnr2000v5_firmware
|
The NETGEAR WNR2000v5 router allows an administrator to perform sensitive actions by invoking the apply.cgi URL on the web server of the device. This special URL is handled by the embedded web server…
|
CWE-20
Improper Input Validation
|
CVE-2016-10176
|
2024-11-21 11:43 |
2017-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266482
|
7.5 |
HIGH
Network
|
squid-cache
|
squid
|
Incorrect HTTP Request header comparison in Squid HTTP Proxy 3.5.0.1 through 3.5.22, and 4.0.1 through 4.0.16 results in Collapsed Forwarding feature mistakenly identifying some private responses as …
|
CWE-697
Incorrect Comparison
|
CVE-2016-10003
|
2024-11-21 11:43 |
2017-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266483
|
7.5 |
HIGH
Network
|
debian squid-cache
|
debian_linux squid
|
Incorrect processing of responses to If-None-Modified HTTP conditional requests in Squid HTTP Proxy 3.1.10 through 3.1.23, 3.2.0.3 through 3.5.22, and 4.0.1 through 4.0.16 leads to client-specific Co…
|
CWE-200
Information Exposure
|
CVE-2016-10002
|
2024-11-21 11:43 |
2017-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266484
|
5.5 |
MEDIUM
Local
|
xen citrix
|
xen xenserver
|
VMFUNC emulation in Xen 4.6.x through 4.8.x on x86 systems using AMD virtualization extensions (aka SVM) allows local HVM guest OS users to cause a denial of service (hypervisor crash) by leveraging …
|
CWE-476
NULL Pointer Dereference
|
CVE-2016-10025
|
2024-11-21 11:43 |
2017-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266485
|
6.0 |
MEDIUM
Local
|
xen citrix
|
xen xenserver
|
Xen through 4.8.x allows local x86 PV guest OS kernel administrators to cause a denial of service (host hang or crash) by modifying the instruction stream asynchronously while performing certain kern…
|
CWE-20
Improper Input Validation
|
CVE-2016-10024
|
2024-11-21 11:43 |
2017-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266486
|
7.8 |
HIGH
Local
|
xen
|
xen
|
Xen through 4.8.x allows local 64-bit x86 HVM guest OS users to gain privileges by leveraging mishandling of SYSCALL singlestep during emulation.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-10013
|
2024-11-21 11:43 |
2017-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266487
|
7.5 |
HIGH
Network
|
php
|
php
|
The php_wddx_pop_element function in ext/wddx/wddx.c in PHP 7.0.x before 7.0.15 and 7.1.x before 7.1.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application c…
|
CWE-476
NULL Pointer Dereference
|
CVE-2016-10162
|
2024-11-21 11:43 |
2017-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266488
|
7.5 |
HIGH
Network
|
php
|
php
|
The object_common1 function in ext/standard/var_unserializer.c in PHP before 5.6.30, 7.0.x before 7.0.15, and 7.1.x before 7.1.1 allows remote attackers to cause a denial of service (buffer over-read…
|
CWE-125
Out-of-bounds Read
|
CVE-2016-10161
|
2024-11-21 11:43 |
2017-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266489
|
9.8 |
CRITICAL
Network
|
php netapp debian
|
php clustered_data_ontap debian_linux
|
Off-by-one error in the phar_parse_pharfile function in ext/phar/phar.c in PHP before 5.6.30 and 7.0.x before 7.0.15 allows remote attackers to cause a denial of service (memory corruption) or possib…
|
CWE-193
Off-by-one Error
|
CVE-2016-10160
|
2024-11-21 11:43 |
2017-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266490
|
7.5 |
HIGH
Network
|
php debian
|
php debian_linux
|
Integer overflow in the phar_parse_pharfile function in ext/phar/phar.c in PHP before 5.6.30 and 7.0.x before 7.0.15 allows remote attackers to cause a denial of service (memory consumption or applic…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2016-10159
|
2024-11-21 11:43 |
2017-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|