|
256961
|
7.0 |
HIGH
Local
|
advantech
|
susiaccess
|
An issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. The directory traversal/file upload error allows an attacker to upload and unpack a zip file.
|
CWE-22
Path Traversal
|
CVE-2016-9351
|
2024-11-21 12:01 |
2017-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256962
|
7.5 |
HIGH
Network
|
advantech
|
susiaccess
|
An issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. An attacker could traverse the file system and extract files that can result in information disclosure.
|
CWE-200
Information Exposure
|
CVE-2016-9349
|
2024-11-21 12:01 |
2017-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256963
|
9.8 |
CRITICAL
Network
|
moxa
|
nport_5100_series_firmware nport_5200_series_firmware nport_5400_series_firmware nport_5600_series_firmware nport_5100a_series_firmware nport_p5150a_series_firmware nport_5200a_seri…
|
An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2.8, NPort 5400 Series versions prior to 3.11, NPor…
|
CWE-287
Improper Authentication
|
CVE-2016-9361
|
2024-11-21 12:01 |
2017-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256964
|
5.3 |
MEDIUM
Network
|
eaton
|
eamxxx_series_epdu_firmware emaxxx_series_epdu_firmware eamaxx_series_epdu_firmware emaaxx_series_epdu_firmware eswaxx_series_epdu_firmware
|
An issue was discovered in certain legacy Eaton ePDUs -- the affected products are past end-of-life (EoL) and no longer supported: EAMxxx prior to June 30, 2015, EMAxxx prior to January 31, 2014, EAM…
|
CWE-22
Path Traversal
|
CVE-2016-9357
|
2024-11-21 12:01 |
2017-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256965
|
5.3 |
MEDIUM
Network
|
puppet
|
puppet_enterprise
|
The Puppet Communications Protocol (PCP) Broker incorrectly validates message header sizes. An attacker could use this to crash the PCP Broker, preventing commands from being sent to agents. This is …
|
CWE-20
Improper Input Validation
|
CVE-2016-9686
|
2024-11-21 12:01 |
2017-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256966
|
4.3 |
MEDIUM
Network
|
ibm
|
rational_requirements_composer rational_doors_next_generation
|
IBM Rational DOORS Next Generation 5.0 and 6.0 discloses sensitive information in error response messages that could be used for further attacks against the system.
|
CWE-200
Information Exposure
|
CVE-2016-9748
|
2024-11-21 12:01 |
2017-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256967
|
9.1 |
CRITICAL
Network
|
saltstack
|
salt
|
Salt before 2015.8.11 allows deleted minions to read or write to minions with the same id, related to caching.
|
CWE-284
Improper Access Control
|
CVE-2016-9639
|
2024-11-21 12:01 |
2017-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256968
|
5.3 |
MEDIUM
Network
|
openafs
|
openafs
|
OpenAFS 1.6.19 and earlier allows remote attackers to obtain sensitive directory information via vectors involving the (1) client cache partition, (2) fileserver vice partition, or (3) certain RPC re…
|
CWE-200
Information Exposure
|
CVE-2016-9772
|
2024-11-21 12:01 |
2017-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256969
|
5.5 |
MEDIUM
Local
|
libtiff debian
|
libtiff debian_linux
|
Integer overflow in the writeBufferToSeparateStrips function in tiffcrop.c in LibTIFF before 4.0.7 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tif file.
|
CWE-125
Out-of-bounds Read
|
CVE-2016-9532
|
2024-11-21 12:01 |
2017-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256970
|
5.5 |
MEDIUM
Local
|
webkit
|
webkit
|
JavaScriptCore in WebKit allows attackers to cause a denial of service (out-of-bounds heap read) via a crafted Javascript file.
|
CWE-125
Out-of-bounds Read
|
CVE-2016-9642
|
2024-11-21 12:01 |
2017-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|