|
265161
|
3.3 |
LOW
Local
|
abb
|
pcm600
|
ABB PCM600 before 2.7 improperly stores PCM600 authentication credentials, which allows local users to obtain sensitive information via unspecified vectors.
|
CWE-255
Credentials Management
|
CVE-2016-4527
|
2024-11-21 11:52 |
2016-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265162
|
6.5 |
MEDIUM
Local
|
abb
|
pcm600
|
ABB PCM600 before 2.7 improperly stores OPC Server IEC61850 passwords in unspecified temporary circumstances, which allows local users to obtain sensitive information via unknown vectors.
|
CWE-310 CWE-284
Cryptographic Issues Improper Access Control
|
CVE-2016-4524
|
2024-11-21 11:52 |
2016-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265163
|
3.3 |
LOW
Local
|
abb
|
pcm600
|
ABB PCM600 before 2.7 improperly stores the main application password after a password change, which allows local users to obtain sensitive information via unspecified vectors.
|
CWE-200
Information Exposure
|
CVE-2016-4516
|
2024-11-21 11:52 |
2016-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265164
|
2.8 |
LOW
Local
|
abb
|
pcm600
|
ABB PCM600 before 2.7 uses an improper hash algorithm for the main application password, which makes it easier for local users to obtain sensitive cleartext information by leveraging read access to t…
|
CWE-310
Cryptographic Issues
|
CVE-2016-4511
|
2024-11-21 11:52 |
2016-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265165
|
5.3 |
MEDIUM
Network
|
kmc_controls
|
bac-5051e_firmware
|
KMC Controls BAC-5051E devices with firmware before E0.2.0.2 allow remote attackers to bypass intended access restrictions and read a configuration file via unspecified vectors.
|
CWE-310 CWE-284
Cryptographic Issues Improper Access Control
|
CVE-2016-4495
|
2024-11-21 11:52 |
2016-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265166
|
8.8 |
HIGH
Network
|
kmc_controls
|
bac-5051e_firmware
|
Cross-site request forgery (CSRF) vulnerability on KMC Controls BAC-5051E devices with firmware before E0.2.0.2 allows remote attackers to hijack the authentication of unspecified victims for request…
|
CWE-352
Origin Validation Error
|
CVE-2016-4494
|
2024-11-21 11:52 |
2016-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265167
|
7.1 |
HIGH
Local
|
debian canonical xmlsoft
|
debian_linux ubuntu_linux libxml2
|
XML external entity (XXE) vulnerability in the xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.4, when not in validating mode, allows context-dependent attackers to read arbitra…
|
CWE-20
Improper Input Validation
|
CVE-2016-4449
|
2024-11-21 11:52 |
2016-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265168
|
9.8 |
CRITICAL
Network
|
hp apple xmlsoft redhat slackware oracle tenable mcafee
|
icewall_federation_agent watchos mac_os_x libxml2 icloud iphone_os enterprise_linux_desktop enterprise_linux_server_aus enterprise_linux_workstation enterprise_linux_server…
|
Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors.
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2016-4448
|
2024-11-21 11:52 |
2016-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265169
|
7.5 |
HIGH
Network
|
hp canonical debian oracle apple xmlsoft mcafee
|
icewall_federation_agent ubuntu_linux debian_linux vm_server itunes iphone_os tvos watchos mac_os_x libxml2 web_gateway
|
The xmlParseElementDecl function in parser.c in libxml2 before 2.9.4 allows context-dependent attackers to cause a denial of service (heap-based buffer underread and application crash) via a crafted …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-4447
|
2024-11-21 11:52 |
2016-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265170
|
9.1 |
CRITICAL
Network
|
trihedral
|
vtscada
|
Directory traversal vulnerability in the WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to read arbitrary files via a crafted pathname.
|
CWE-22
Path Traversal
|
CVE-2016-4532
|
2024-11-21 11:52 |
2016-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|