|
265371
|
9.8 |
CRITICAL
Network
|
milesight
|
ip_security_camera_firmware
|
Milesight IP security cameras through 2016-11-14 have a hardcoded SSL private key under the /etc/config directory.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2016-2357
|
2024-11-21 11:48 |
2019-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265372
|
9.8 |
CRITICAL
Network
|
milesight
|
ip_security_camera_firmware
|
Milesight IP security cameras through 2016-11-14 have a buffer overflow in a web application via a long username or password.
|
CWE-120
Classic Buffer Overflow
|
CVE-2016-2356
|
2024-11-21 11:48 |
2019-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265373
|
5.5 |
MEDIUM
Local
|
audacityteam
|
audacity
|
Audacity before 2.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted MP2 file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-2541
|
2024-11-21 11:48 |
2018-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265374
|
5.5 |
MEDIUM
Local
|
audacityteam
|
audacity
|
Audacity before 2.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted FORMATCHUNK structure.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-2540
|
2024-11-21 11:48 |
2018-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265375
|
6.5 |
MEDIUM
Network
|
pl\/java_project
|
pl\/java
|
PostgreSQL PL/Java before 1.5.0 allows remote authenticated users to alter type mappings for types they do not own.
|
CWE-269
Improper Privilege Management
|
CVE-2016-2192
|
2024-11-21 11:48 |
2017-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265376
|
5.9 |
MEDIUM
Network
|
invisioncommunity
|
invision_power_board
|
Invision Power Services (IPS) Community Suite before 4.1.9 makes session hijack easier by relying on the PHP uniqid function without the more_entropy flag. Attackers can guess an Invision Power Board…
|
CWE-331
Insufficient Entropy
|
CVE-2016-2564
|
2024-11-21 11:48 |
2017-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265377
|
8.8 |
HIGH
Adjacent
|
google
|
android
|
The Broadcom Wi-Fi driver for Android, as used by BlackBerry smartphones before Build AAE570, allows remote attackers to execute arbitrary code in the context of the kernel.
|
CWE-284
Improper Access Control
|
CVE-2016-2433
|
2024-11-21 11:48 |
2017-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265378
|
7.8 |
HIGH
Local
|
opensuse debian lhasa_project
|
leap opensuse debian_linux lhasa
|
Integer underflow in the decode_level3_header function in lib/lha_file_header.c in Lhasa before 0.3.1 allows remote attackers to execute arbitrary code via a crafted archive.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2016-2347
|
2024-11-21 11:48 |
2017-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265379
|
3.3 |
LOW
Local
|
samsung
|
galaxy_s6_firmware galaxy_note_3_firmware
|
secfilter in the Samsung kernel for Android on SM-N9005 build N9005XXUGBOB6 (Note 3) and SM-G920F build G920FXXU2COH2 (Galaxy S6) devices allows attackers to bypass URL filtering by inserting an "exc…
|
CWE-20
Improper Input Validation
|
CVE-2016-2567
|
2024-11-21 11:48 |
2017-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265380
|
9.8 |
CRITICAL
Network
|
samsung
|
galaxy_s6_firmware
|
Samsung SecEmailSync on SM-G920F build G920FXXU2COH2 (Galaxy S6) devices has SQL injection, aka SVE-2015-5081.
|
CWE-89
SQL Injection
|
CVE-2016-2566
|
2024-11-21 11:48 |
2017-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|