|
264921
|
6.1 |
MEDIUM
Network
|
nodejs suse
|
node.js linux_enterprise
|
CRLF injection vulnerability in the ServerResponse#writeHead function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 allows remote attackers to inject…
|
CWE-113
HTTP Response Splitting
|
CVE-2016-5325
|
2024-11-21 11:54 |
2016-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264922
|
5.9 |
MEDIUM
Network
|
google
|
android
|
The GPS component in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 allows man-in-the-middle attackers to cause a denial of service…
|
CWE-399
Resource Management Errors
|
CVE-2016-5348
|
2024-11-21 11:54 |
2016-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264923
|
9.8 |
CRITICAL
Network
|
linux
|
linux_kernel
|
drivers/soc/qcom/qdsp6v2/voice_svc.c in the QDSP6v2 Voice Service driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other product…
|
CWE-120
Classic Buffer Overflow
|
CVE-2016-5343
|
2024-11-21 11:54 |
2016-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264924
|
9.8 |
CRITICAL
Network
|
f5
|
big-ip_local_traffic_manager
|
F5 BIG-IP LTM systems 11.x before 11.2.1 HF16, 11.3.x, 11.4.x before 11.4.1 HF11, 11.5.0, 11.5.1 before HF11, 11.5.2, 11.5.3, 11.5.4 before HF2, 11.6.0 before HF8, 11.6.1 before HF1, 12.0.0 before HF…
|
CWE-284
Improper Access Control
|
CVE-2016-5745
|
2024-11-21 11:54 |
2016-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264925
|
9.8 |
CRITICAL
Network
|
animas
|
onetouch_ping_firmware
|
Johnson & Johnson Animas OneTouch Ping devices mishandle acknowledgements, which makes it easier for remote attackers to bypass authentication via a custom communication protocol.
|
CWE-287
Improper Authentication
|
CVE-2016-5686
|
2024-11-21 11:54 |
2016-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264926
|
3.3 |
LOW
Local
|
redhat
|
enterprise_virtualization
|
The ovirt-engine-provisiondb utility in Red Hat Enterprise Virtualization (RHEV) Engine 4.0 allows local users to obtain sensitive database provisioning information by reading log files.
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2016-5432
|
2024-11-21 11:54 |
2016-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264927
|
5.4 |
MEDIUM
Network
|
redhat
|
jboss_bpm_suite
|
Cross-site scripting (XSS) vulnerability in Business Process Editor in Red Hat JBoss BPM Suite before 6.3.3 allows remote authenticated users to inject arbitrary web script or HTML by levering permis…
|
CWE-79
Cross-site Scripting
|
CVE-2016-5398
|
2024-11-21 11:54 |
2016-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264928
|
9.8 |
CRITICAL
Network
|
f5
|
big-ip_policy_enforcement_manager big-ip_local_traffic_manager big-ip_websafe big-ip_link_controller big-ip_application_acceleration_manager big-ip_access_policy_manager big-ip_adva…
|
Virtual servers in F5 BIG-IP systems 11.5.0, 11.5.1 before HF11, 11.5.2, 11.5.3, 11.5.4 before HF2, 11.6.0 before HF8, 11.6.1 before HF1, 12.0.0 before HF4, and 12.1.0 before HF2, when configured wit…
|
CWE-284
Improper Access Control
|
CVE-2016-5700
|
2024-11-21 11:54 |
2016-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264929
|
5.1 |
MEDIUM
Local
|
opensuse yast
|
libstorage-ng yast-storage libstorage leap
|
libstorage, libstorage-ng, and yast-storage improperly store passphrases for encrypted storage devices in a temporary file on disk, which might allow local users to obtain sensitive information by re…
|
NVD-CWE-Other
|
CVE-2016-5746
|
2024-11-21 11:54 |
2016-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264930
|
8.8 |
HIGH
Network
|
redhat
|
jboss_enterprise_application_platform
|
The domain controller in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2 allows remote authenticated users to gain privileges by leveraging failure to propagate administrative RB…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-5406
|
2024-11-21 11:54 |
2016-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|