|
265481
|
7.8 |
HIGH
Local
|
symantec
|
mail_security_for_microsoft_exchange norton_power_eraser protection_engine endpoint_protection message_gateway norton_360 norton_antivirus norton_internet_security norton_secu…
|
The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SE…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-2211
|
2024-11-21 11:48 |
2016-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265482
|
7.3 |
HIGH
Local
|
symantec
|
mail_security_for_microsoft_exchange norton_power_eraser protection_engine endpoint_protection message_gateway norton_360 norton_antivirus norton_internet_security norton_secu…
|
Buffer overflow in Dec2LHA.dll in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-2210
|
2024-11-21 11:48 |
2016-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265483
|
7.3 |
HIGH
Local
|
symantec
|
mail_security_for_microsoft_exchange norton_power_eraser protection_engine endpoint_protection message_gateway norton_360 norton_antivirus norton_internet_security norton_secu…
|
Buffer overflow in Dec2SS.dll in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway;…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-2209
|
2024-11-21 11:48 |
2016-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265484
|
8.4 |
HIGH
Local
|
symantec
|
mail_security_for_microsoft_exchange norton_power_eraser protection_engine endpoint_protection message_gateway norton_360 norton_antivirus norton_internet_security norton_secu…
|
The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SE…
|
CWE-20
Improper Input Validation
|
CVE-2016-2207
|
2024-11-21 11:48 |
2016-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265485
|
7.5 |
HIGH
Network
|
fonality
|
hud_web fonality
|
The Chrome HUDweb plugin before 2016-05-05 for Fonality (previously trixbox Pro) 12.6 through 14.1i uses the same hardcoded private key across different customers' installations, which allows remote …
|
CWE-310 NVD-CWE-Other
Cryptographic Issues
|
CVE-2016-2364
|
2024-11-21 11:48 |
2016-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265486
|
7.8 |
HIGH
Local
|
fonality
|
fonality
|
Fonality (previously trixbox Pro) 12.6 through 14.1i before 2016-06-01 uses weak permissions for the /var/www/rpc/surun script, which allows local users to obtain root access for unspecified command …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-2363
|
2024-11-21 11:48 |
2016-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265487
|
9.8 |
CRITICAL
Network
|
fonality
|
fonality
|
Fonality (previously trixbox Pro) 12.6 through 14.1i before 2016-06-01 has a hardcoded password for the FTP account, which allows remote attackers to obtain access via a (1) FTP or (2) SSH connection.
|
NVD-CWE-Other
|
CVE-2016-2362
|
2024-11-21 11:48 |
2016-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265488
|
6.0 |
MEDIUM
Local
|
qemu canonical
|
qemu ubuntu_linux
|
The ne2000_receive function in the NE2000 NIC emulation support (hw/net/ne2000.c) in QEMU before 2.5.1 allows local guest OS administrators to cause a denial of service (infinite loop and QEMU proces…
|
CWE-20
Improper Input Validation
|
CVE-2016-2841
|
2024-11-21 11:48 |
2016-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265489
|
7.1 |
HIGH
Local
|
qemu
|
qemu
|
Multiple integer overflows in the USB Net device emulator (hw/usb/dev-network.c) in QEMU before 2.5.1 allow local guest OS administrators to cause a denial of service (QEMU process crash) or obtain s…
|
CWE-189
Numeric Errors
|
CVE-2016-2538
|
2024-11-21 11:48 |
2016-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265490
|
6.5 |
MEDIUM
Local
|
qemu canonical
|
qemu ubuntu_linux
|
The is_rndis function in the USB Net device emulator (hw/usb/dev-network.c) in QEMU before 2.5.1 does not properly validate USB configuration descriptor objects, which allows local guest OS administr…
|
NVD-CWE-Other
|
CVE-2016-2392
|
2024-11-21 11:48 |
2016-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|