|
265471
|
7.8 |
HIGH
Local
|
google
|
android
|
The Qualcomm GPU driver in Android before 2016-07-05 on Nexus 5X and 6P devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28084795 and Qualcomm internal …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-2503
|
2024-11-21 11:48 |
2016-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265472
|
7.8 |
HIGH
Local
|
google
|
android
|
drivers/usb/gadget/f_serial.c in the Qualcomm USB driver in Android before 2016-07-05 on Nexus 5X and 6P devices allows attackers to gain privileges via a large size in a GSER_IOCTL ioctl call, aka A…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-2502
|
2024-11-21 11:48 |
2016-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265473
|
7.8 |
HIGH
Local
|
google
|
android
|
The Qualcomm camera driver in Android before 2016-07-05 on Nexus 5X, 6, 6P, and 7 (2013) devices allows attackers to gain privileges via a crafted application, aka Android internal bug 27890772 and Q…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-2501
|
2024-11-21 11:48 |
2016-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265474
|
8.0 |
HIGH
Network
|
ibm
|
websphere_commerce
|
Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Commerce 7.0 Feature Pack 8, 8.0.0.x before 8.0.0.10, and 8.0.1.x before 8.0.1.2 allows remote authenticated users to hijack the authe…
|
CWE-352
Origin Validation Error
|
CVE-2016-2863
|
2024-11-21 11:48 |
2016-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265475
|
6.1 |
MEDIUM
Network
|
ibm
|
websphere_commerce
|
Cross-site scripting (XSS) vulnerability in IBM WebSphere Commerce 6.0 through 6.0.0.11, 7.0 before 7.0.0.9 cumulative iFix 3, and 8.0 before 8.0.0.5 allows remote attackers to inject arbitrary web s…
|
CWE-79
Cross-site Scripting
|
CVE-2016-2862
|
2024-11-21 11:48 |
2016-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265476
|
5.3 |
MEDIUM
Network
|
ibm
|
qradar_security_information_and_event_manager security_qradar_incident_forensics
|
Directory traversal vulnerability in IBM Security QRadar SIEM 7.2.x before 7.2.7 and QRadar Incident Forensics 7.2.x before 7.2.7 allows remote attackers to read arbitrary files via a crafted URL.
|
CWE-22
Path Traversal
|
CVE-2016-2872
|
2024-11-21 11:48 |
2016-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265477
|
2.7 |
LOW
Network
|
ibm
|
websphere_datapower_xc10_appliance_firmware
|
Buffer overflow in the CLI on IBM WebSphere DataPower XC10 appliances 2.1 and 2.5 allows remote authenticated users to cause a denial of service via unspecified vectors.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-2870
|
2024-11-21 11:48 |
2016-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265478
|
2.7 |
LOW
Network
|
ibm
|
qradar_security_information_and_event_manager
|
IBM Security QRadar SIEM 7.2.x before 7.2.7 allows remote authenticated administrators to read arbitrary files via XML data containing an external entity declaration in conjunction with an entity ref…
|
NVD-CWE-Other
|
CVE-2016-2868
|
2024-11-21 11:48 |
2016-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265479
|
7.0 |
HIGH
Local
|
ibm
|
streams infosphere_streams
|
IBM InfoSphere Streams before 4.0.1.2 and IBM Streams before 4.1.1.1 do not properly implement the runAsUser feature, which allows local users to obtain root group privileges via unspecified vectors.
|
CWE-254
7PK - Security Features
|
CVE-2016-2867
|
2024-11-21 11:48 |
2016-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265480
|
3.7 |
LOW
Network
|
ibm
|
websphere_extreme_scale
|
IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3, 7.1.1 before 7.1.1.1, 8.5 before 8.5.0.3, and 8.6 before 8.6.0.8 does not properly encrypt data, which makes it easier for remote attackers to obtain…
|
CWE-200
Information Exposure
|
CVE-2016-2861
|
2024-11-21 11:48 |
2016-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|