|
265681
|
6.1 |
MEDIUM
Network
|
cisco
|
firesight_system_software
|
Cross-site scripting (XSS) vulnerability in the Device Management UI in the management interface in Cisco FireSIGHT System Software 6.1.0 allows remote attackers to inject arbitrary web script or HTM…
|
CWE-79
Cross-site Scripting
|
CVE-2016-1355
|
2024-11-21 11:46 |
2016-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265682
|
6.1 |
MEDIUM
Network
|
cisco
|
unified_communications_domain_manager
|
Cross-site scripting (XSS) vulnerability in Cisco Unified Communications Domain Manager (UCDM) 8.x before 8.1.1 allows remote attackers to inject arbitrary web script or HTML via crafted markup data,…
|
CWE-79
Cross-site Scripting
|
CVE-2016-1354
|
2024-11-21 11:46 |
2016-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265683
|
9.8 |
CRITICAL
Network
|
samsung sun zyxel zzinc
|
x14j_firmware opensolaris gs1900-10hp_firmware keymouse_firmware
|
Cisco NX-OS 6.0(2)U6(1) through 6.0(2)U6(5) on Nexus 3000 devices and 6.0(2)A6(1) through 6.0(2)A6(5) and 6.0(2)A7(1) on Nexus 3500 devices has hardcoded credentials, which allows remote attackers to…
|
CWE-287
Improper Authentication
|
CVE-2016-1329
|
2024-11-21 11:46 |
2016-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265684
|
5.3 |
MEDIUM
Network
|
cisco
|
videoscape_distribution_suite_for_internet_streaming
|
The TCP implementation in Cisco Videoscape Distribution Suite for Internet Streaming (VDS-IS) 3.3(0), 3.3(1), 4.0(0), and 4.1(0) does not properly initiate new TCP sessions when a previous session is…
|
CWE-399
Resource Management Errors
|
CVE-2016-1353
|
2024-11-21 11:46 |
2016-03-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265685
|
5.3 |
MEDIUM
Network
|
cisco
|
firepower_management_center
|
The device login page in Cisco FirePOWER Management Center 5.3 through 6.0.0.1 allows remote attackers to obtain potentially sensitive software-version information by reading help files, aka Bug ID C…
|
CWE-200
Information Exposure
|
CVE-2016-1342
|
2024-11-21 11:46 |
2016-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265686
|
8.8 |
HIGH
Network
|
cisco
|
application_control_engine_software
|
The Device Manager GUI in Cisco Application Control Engine (ACE) 4710 A5 before A5(3.1) allows remote authenticated users to bypass intended RBAC restrictions and execute arbitrary CLI commands with …
|
CWE-78
OS Command
|
CVE-2016-1297
|
2024-11-21 11:46 |
2016-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265687
|
9.8 |
CRITICAL
Network
|
cisco
|
nx-os
|
Cisco NX-OS 7.0(1)N1(1), 7.0(1)N1(3), and 7.0(4)N1(1) on Nexus 2000 Fabric Extender devices has a blank root password, which allows local users to gain privileges via unspecified vectors, aka Bug ID …
|
CWE-255 CWE-264
Credentials Management Permissions, Privileges, and Access Controls
|
CVE-2016-1341
|
2024-11-21 11:46 |
2016-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265688
|
9.8 |
CRITICAL
Network
|
google novell opensuse debian
|
chrome suse_package_hub_for_suse_linux_enterprise leap opensuse debian_linux
|
Google Chrome before 48.0.2564.116 allows remote attackers to bypass the Blink Same Origin Policy and a sandbox protection mechanism via unspecified vectors.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-1629
|
2024-11-21 11:46 |
2016-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265689
|
6.3 |
MEDIUM
Network
|
google debian
|
chrome debian_linux
|
pi.c in OpenJPEG, as used in PDFium in Google Chrome before 48.0.2564.109, does not validate a certain precision value, which allows remote attackers to execute arbitrary code or cause a denial of se…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-1628
|
2024-11-21 11:46 |
2016-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265690
|
7.5 |
HIGH
Network
|
cisco
|
asr_5000_series_software
|
The SSH implementation in Cisco StarOS before 19.3.M0.62771 and 20.x before 20.0.M0.62768 on ASR 5000 devices mishandles a multi-user public-key authentication configuration, which allows remote auth…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-1335
|
2024-11-21 11:46 |
2016-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|