|
257111
|
9.1 |
CRITICAL
Network
|
simplesamlphp
|
simplesamlphp saml2
|
The validateSignature method in the SAML2\Utils class in SimpleSAMLphp before 1.14.10 and simplesamlphp/saml2 library before 1.9.1, 1.10.x before 1.10.3, and 2.x before 2.3.3 allows remote attackers …
|
CWE-399
Resource Management Errors
|
CVE-2016-9814
|
2024-11-21 12:01 |
2017-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257112
|
5.5 |
MEDIUM
Local
|
imagemagick
|
imagemagick
|
Heap-based buffer overflow in the IsPixelGray function in MagickCore/pixel-accessor.h in ImageMagick 7.0.3.8 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a craft…
|
CWE-119 CWE-125
Incorrect Access of Indexable Resource ('Range Error') Out-of-bounds Read
|
CVE-2016-9773
|
2024-11-21 12:01 |
2017-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257113
|
7.5 |
HIGH
Local
|
citrix
|
xenserver
|
The (1) ioport_read and (2) ioport_write functions in Xen, when qemu is used as a device model within Xen, might allow local x86 HVM guest OS administrators to gain qemu process privileges via vector…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-9637
|
2024-11-21 12:01 |
2017-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257114
|
9.1 |
CRITICAL
Network
|
ibm
|
websphere_message_broker integration_bus
|
IBM Integration Bus 9.0 and 10.0 and WebSphere Message Broker SOAP FLOWS is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remot…
|
CWE-611
XXE
|
CVE-2016-9706
|
2024-11-21 12:01 |
2017-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257115
|
7.8 |
HIGH
Local
|
jasper_project debian redhat
|
jasper debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_tus enterprise_linux_server_aus enterprise_linux_eus
|
Stack-based buffer overflow in the jpc_tsfb_getbands2 function in jpc_tsfb.c in JasPer before 1.900.30 allows remote attackers to have unspecified impact via a crafted image.
|
CWE-787
Out-of-bounds Write
|
CVE-2016-9560
|
2024-11-21 12:01 |
2017-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257116
|
5.3 |
MEDIUM
Physics
|
bd
|
alaris_8015_pc_unit
|
An issue was discovered in Becton, Dickinson and Company (BD) Alaris 8015 Point of Care (PC) unit, Version 9.5 and prior versions, and Version 9.7. An unauthorized user with physical access to an Ala…
|
CWE-255
Credentials Management
|
CVE-2016-9355
|
2024-11-21 12:01 |
2017-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257117
|
6.1 |
MEDIUM
Network
|
moxa
|
nport_5100_series_firmware nport_5200_series_firmware nport_5400_series_firmware nport_5600_series_firmware nport_5100a_series_firmware nport_p5150a_series_firmware nport_5200a_seri…
|
An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2.8, NPort 5400 Series versions prior to 3.11, NPor…
|
CWE-79
Cross-site Scripting
|
CVE-2016-9371
|
2024-11-21 12:01 |
2017-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257118
|
9.8 |
CRITICAL
Network
|
moxa
|
nport_5100_series_firmware nport_5200_series_firmware nport_5400_series_firmware nport_5600_series_firmware nport_5100a_series_firmware nport_p5150a_series_firmware nport_5200a_seri…
|
An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2.8, NPort 5400 Series versions prior to 3.11, NPor…
|
CWE-287
Improper Authentication
|
CVE-2016-9369
|
2024-11-21 12:01 |
2017-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257119
|
7.5 |
HIGH
Network
|
fidelex
|
fx-2030a_firmware fx-2030a-basic_firmware
|
An issue was discovered in Fidelix FX-20 series controllers, versions prior to 11.50.19. Arbitrary file reading via path traversal allows an attacker to access arbitrary files and directories on the …
|
CWE-22
Path Traversal
|
CVE-2016-9364
|
2024-11-21 12:01 |
2017-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257120
|
9.1 |
CRITICAL
Network
|
wago
|
pfc200_firmware 750-xxxx_series_firmware 758-xxxx_series_firmware
|
An issue was discovered in WAGO 750-8202/PFC200 prior to FW04 (released August 2015), WAGO 750-881 prior to FW09 (released August 2016), and WAGO 0758-0874-0000-0111. By accessing a specific uniform …
|
CWE-287
Improper Authentication
|
CVE-2016-9362
|
2024-11-21 12:01 |
2017-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|