|
258071
|
8.8 |
HIGH
Network
|
spice_project redhat debian
|
spice enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server debian_linux enterprise_linux_server_aus enterprise_linux_server_eus
|
A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An authenticated attacker could send crafted messages to the SPICE server causing a heap overflow leading to …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-9577
|
2024-11-21 12:01 |
2018-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258072
|
5.5 |
MEDIUM
Local
|
theforeman redhat
|
katello satellite satellite_capsule
|
A flaw was found in katello-debug before 3.4.0 where certain scripts and log files used insecure temporary files. A local user could exploit this flaw to conduct a symbolic-link attack, allowing them…
|
CWE-59
Link Following
|
CVE-2016-9595
|
2024-11-21 12:01 |
2018-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258073
|
5.9 |
MEDIUM
Network
|
mozilla
|
network_security_services
|
nss before version 3.30 is vulnerable to a remote denial of service during the session handshake when using SessionTicket extension and ECDHE-ECDSA.
|
CWE-384
Session Fixation
|
CVE-2016-9574
|
2024-11-21 12:01 |
2018-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258074
|
6.1 |
MEDIUM
Network
|
accellion
|
ftp_server
|
Accellion FTP server prior to version FTA_9_12_220 uses the Accusoft Prizm Content flash component, which contains multiple parameters (customTabCategoryName, customButton1Image) that are vulnerable …
|
CWE-79
Cross-site Scripting
|
CVE-2016-9500
|
2024-11-21 12:01 |
2018-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258075
|
5.3 |
MEDIUM
Network
|
accellion
|
ftp_server
|
Accellion FTP server prior to version FTA_9_12_220 only returns the username in the server response if the username is invalid. An attacker may use this information to determine valid user accounts a…
|
CWE-200
Information Exposure
|
CVE-2016-9499
|
2024-11-21 12:01 |
2018-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258076
|
8.8 |
HIGH
Adjacent
|
hughes
|
hn7740s_firmware dw7000_firmware hn7000s_firmware hn7000sm_firmware
|
Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, is vulnerable to an authentication bypass using an alternate path or channel. By default, port 1953 is accessible…
|
CWE-287
Improper Authentication
|
CVE-2016-9497
|
2024-11-21 12:01 |
2018-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258077
|
6.5 |
MEDIUM
Adjacent
|
hughes
|
hn7740s_firmware dw7000_firmware hn7000s_firmware hn7000sm_firmware
|
Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, lacks authentication. An unauthenticated user may send an HTTP GET request to http://[ip]/com/gatewayreset or htt…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2016-9496
|
2024-11-21 12:01 |
2018-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258078
|
8.8 |
HIGH
Adjacent
|
hughes
|
hn7740s_firmware dw7000_firmware hn7000s_firmware hn7000sm_firmware
|
Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, uses hard coded credentials. Access to the device's default telnet port (23) can be obtained through using one of…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2016-9495
|
2024-11-21 12:01 |
2018-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258079
|
6.5 |
MEDIUM
Adjacent
|
hughes
|
hn7740s_firmware dw7000_firmware hn7000s_firmware hn7000sm_firmware
|
Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, are potentially vulnerable to improper input validation. The device's advanced status web page that is linked to …
|
CWE-20
Improper Input Validation
|
CVE-2016-9494
|
2024-11-21 12:01 |
2018-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258080
|
4.9 |
MEDIUM
Network
|
zohocorp
|
manageengine_applications_manager
|
ManageEngine Applications Manager 12 and 13 before build 13690 allows an authenticated user, who is able to access /register.do page (most likely limited to administrator), to browse the filesystem a…
|
CWE-200
Information Exposure
|
CVE-2016-9491
|
2024-11-21 12:01 |
2018-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|