|
264801
|
6.1 |
MEDIUM
Network
|
huawei
|
fusionaccess
|
CRLF injection vulnerability in Huawei FusionAccess before V100R006C00 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
|
CWE-113
HTTP Response Splitting
|
CVE-2016-6839
|
2024-11-21 11:56 |
2016-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264802
|
5.3 |
MEDIUM
Network
|
huawei_firmware huawei
|
s12700 s9700_firmware s7700_firmware s9300_firmware
|
Huawei S7700, S9300, S9700, and S12700 devices with software before V200R008C00SPC500 use random numbers with insufficient entropy to generate self-signed certificates, which makes it easier for remo…
|
CWE-200
Information Exposure
|
CVE-2016-6670
|
2024-11-21 11:56 |
2016-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264803
|
7.5 |
HIGH
Network
|
huawei
|
rh1288_v3_server_firmware rh2288_v3_server_firmware x6800_v3_server_firmware xh620_v3_server_firmware ch121_v3_server_firmware ch140_v3_server_firmware ch220_v3_server_firmware c…
|
Huawei X6800 and XH620 V3 servers with software before V100R003C00SPC606, RH1288 V3 servers with software before V100R003C00SPC613, RH2288 V3 servers with software before V100R003C00SPC617, CH140 V3 …
|
CWE-310 CWE-200
Cryptographic Issues Information Exposure
|
CVE-2016-6838
|
2024-11-21 11:56 |
2016-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264804
|
9.8 |
CRITICAL
Network
|
huawei
|
rh1288_v3_server_firmware rh2288_v3_server_firmware rh2288h_v3_server_firmware xh620_v3_server_firmware xh622_v3_server_firmware xh628_v3_server_firmware
|
Huawei XH620 V3, XH622 V3, and XH628 V3 servers with software before V100R003C00SPC610, RH1288 V3 servers with software before V100R003C00SPC613, RH2288 V3 servers with software before V100R003C00SPC…
|
CWE-285
Improper Authorization
|
CVE-2016-6825
|
2024-11-21 11:56 |
2016-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264805
|
7.5 |
HIGH
Network
|
fedoraproject opensuse canonical gnome
|
fedora leap opensuse ubuntu_linux eye_of_gnome
|
Eye of GNOME (aka eog) 3.16.5, 3.17.x, 3.18.x before 3.18.3, 3.19.x, and 3.20.x before 3.20.4, when used with glib before 2.44.1, allow remote attackers to cause a denial of service (out-of-bounds wr…
|
CWE-787
Out-of-bounds Write
|
CVE-2016-6855
|
2024-11-21 11:56 |
2016-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264806
|
8.1 |
HIGH
Network
|
cisco
|
media_origination_system_suite
|
Media Origination System Suite Software 2.6 and earlier in Cisco Virtual Media Packager (VMP) allows remote attackers to bypass authentication and make arbitrary Platform and Applications Manager (PA…
|
CWE-287
Improper Authentication
|
CVE-2016-6377
|
2024-11-21 11:56 |
2016-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264807
|
8.6 |
HIGH
Network
|
vbulletin
|
vbulletin
|
The media-file upload feature in vBulletin before 3.8.7 Patch Level 6, 3.8.8 before Patch Level 2, 3.8.9 before Patch Level 1, 4.x before 4.2.2 Patch Level 6, 4.2.3 before Patch Level 2, 5.x before 5…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2016-6483
|
2024-11-21 11:56 |
2016-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264808
|
6.5 |
MEDIUM
Adjacent
|
cisco
|
wireless_lan_controller wireless_lan_controller_7.2 wireless_lan_controller_7.0 wireless_lan_controller_7.4 wireless_lan_controller_6.0 wireless_lan_controller_7.1
|
The Adaptive Wireless Intrusion Prevention System (wIPS) feature on Cisco Wireless LAN Controller (WLC) devices before 8.0.140.0, 8.1.x and 8.2.x before 8.2.121.0, and 8.3.x before 8.3.102.0 allows r…
|
CWE-399
Resource Management Errors
|
CVE-2016-6376
|
2024-11-21 11:56 |
2016-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264809
|
9.8 |
CRITICAL
Network
|
citrix
|
xenapp xendesktop
|
Citrix XenApp 6.x before 6.5 HRP07 and 7.x before 7.9 and Citrix XenDesktop before 7.9 might allow attackers to weaken an unspecified security mitigation via vectors related to memory permission.
|
CWE-254
7PK - Security Features
|
CVE-2016-6493
|
2024-11-21 11:56 |
2016-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264810
|
8.6 |
HIGH
Network
|
sophos
|
mobile_control_eas_proxy
|
Sophos EAS Proxy before 6.2.0 for Sophos Mobile Control, when Lotus Traveler is enabled, allows remote attackers to access arbitrary web-resources from the backend mail system via a request for the r…
|
CWE-254
7PK - Security Features
|
CVE-2016-6597
|
2024-11-21 11:56 |
2016-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|