|
264941
|
7.5 |
HIGH
Network
|
osram
|
lightify_home
|
OSRAM SYLVANIA Osram Lightify Home through 2016-07-26 allows Zigbee replay.
|
CWE-284
Improper Access Control
|
CVE-2016-5054
|
2024-11-21 11:53 |
2017-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264942
|
9.8 |
CRITICAL
Network
|
osram
|
lightify_home
|
OSRAM SYLVANIA Osram Lightify Home before 2016-07-26 allows remote attackers to execute arbitrary commands via TCP port 4000.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2016-5053
|
2024-11-21 11:53 |
2017-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264943
|
7.5 |
HIGH
Network
|
osram
|
lightify_home
|
OSRAM SYLVANIA Osram Lightify Home through 2016-07-26 does not use SSL pinning.
|
CWE-254
7PK - Security Features
|
CVE-2016-5052
|
2024-11-21 11:53 |
2017-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264944
|
7.5 |
HIGH
Network
|
osram
|
lightify_home
|
OSRAM SYLVANIA Osram Lightify Home before 2016-07-26 stores a PSK in cleartext under /private/var/mobile/Containers/Data/Application.
|
CWE-200
Information Exposure
|
CVE-2016-5051
|
2024-11-21 11:53 |
2017-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264945
|
5.5 |
MEDIUM
Local
|
apache
|
ambari
|
Apache Ambari 2.x before 2.4.0 includes KDC administrator passwords on the kadmin command line, which allows local users to obtain sensitive information via a process listing.
|
CWE-200
Information Exposure
|
CVE-2016-4976
|
2024-11-21 11:53 |
2017-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264946
|
7.5 |
HIGH
Network
|
openslp
|
openslp
|
The _xrealloc function in xlsp_xmalloc.c in OpenSLP 2.0.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a large number of crafted packets, which trigge…
|
CWE-476
NULL Pointer Dereference
|
CVE-2016-4912
|
2024-11-21 11:53 |
2017-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264947
|
6.5 |
MEDIUM
Network
|
juniper
|
junos_space
|
XML entity injection in Junos Space before 15.2R2 allows attackers to cause a denial of service.
|
CWE-611
XXE
|
CVE-2016-4931
|
2024-11-21 11:53 |
2017-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264948
|
6.1 |
MEDIUM
Network
|
juniper
|
junos_space
|
Cross-site scripting (XSS) vulnerability in Junos Space before 15.2R2 allows remote attackers to steal sensitive information or perform certain administrative actions.
|
CWE-79
Cross-site Scripting
|
CVE-2016-4930
|
2024-11-21 11:53 |
2017-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264949
|
8.8 |
HIGH
Network
|
juniper
|
junos_space
|
Command injection vulnerability in Junos Space before 15.2R2 allows attackers to execute arbitrary code as a root user.
|
CWE-77
Command Injection
|
CVE-2016-4929
|
2024-11-21 11:53 |
2017-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264950
|
8.8 |
HIGH
Network
|
juniper
|
junos_space
|
Cross site request forgery vulnerability in Junos Space before 15.2R2 allows remote attackers to perform certain administrative actions on Junos Space.
|
CWE-352
Origin Validation Error
|
CVE-2016-4928
|
2024-11-21 11:53 |
2017-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|