|
265841
|
7.2 |
HIGH
Network
|
osclass
|
osclass
|
osClass 3.6.1 allows oc-admin/plugins.php Directory Traversal via the plugin parameter. This is exploitable for remote PHP code execution because an administrator can upload an image that contains PH…
|
CWE-22 CWE-434
Path Traversal Unrestricted Upload of File with Dangerous Type
|
CVE-2016-10751
|
2024-11-21 11:44 |
2019-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265842
|
8.1 |
HIGH
Network
|
hazelcast
|
hazelcast
|
In Hazelcast before 3.11, the cluster join procedure is vulnerable to remote code execution via Java deserialization. If an attacker can reach a listening Hazelcast instance with a crafted JoinReques…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2016-10750
|
2024-11-21 11:44 |
2019-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265843
|
6.1 |
MEDIUM
Network
|
tp-link
|
archer_cr700_firmware
|
TP-Link Archer CR-700 1.0.6 devices have an XSS vulnerability that can be introduced into the admin account through a DHCP request, allowing the attacker to steal the cookie information, which contai…
|
CWE-79
Cross-site Scripting
|
CVE-2016-10719
|
2024-11-21 11:44 |
2019-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265844
|
9.8 |
CRITICAL
Network
|
cjson_project
|
cjson
|
parse_string in cJSON.c in cJSON before 2016-10-02 has a buffer over-read, as demonstrated by a string that begins with a " character and ends with a \ character.
|
CWE-125
Out-of-bounds Read
|
CVE-2016-10749
|
2024-11-21 11:44 |
2019-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265845
|
7.5 |
HIGH
Network
|
redhat debian
|
libvirt debian_linux
|
libvirt-domain.c in libvirt before 1.3.1 supports virDomainGetTime API calls by guest agents with an RO connection, even though an RW connection was supposed to be required, a different vulnerability…
|
CWE-254
7PK - Security Features
|
CVE-2016-10746
|
2024-11-21 11:44 |
2019-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265846
|
8.6 |
HIGH
Network
|
palletsprojects
|
jinja
|
In Pallets Jinja before 2.8.1, str.format allows a sandbox escape.
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2016-10745
|
2024-11-21 11:44 |
2019-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265847
|
6.1 |
MEDIUM
Network
|
select2
|
select2
|
In Select2 through 4.0.5, as used in Snipe-IT and other products, rich selectlists allow XSS. This affects use cases with Ajax remote data loading when HTML templates are used to display listbox data.
|
CWE-79
Cross-site Scripting
|
CVE-2016-10744
|
2024-11-21 11:44 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265848
|
7.5 |
HIGH
Network
|
w1.fi
|
hostapd
|
hostapd before 2.6 does not prevent use of the low-quality PRNG that is reached by an os_random() function call.
|
CWE-332
Insufficient Entropy in PRNG
|
CVE-2016-10743
|
2024-11-21 11:44 |
2019-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265849
|
6.1 |
MEDIUM
Network
|
zabbix debian
|
zabbix debian_linux
|
Zabbix before 2.2.21rc1, 3.x before 3.0.13rc1, 3.1.x and 3.2.x before 3.2.10rc1, and 3.3.x and 3.4.x before 3.4.4rc1 allows open redirect via the request parameter.
|
CWE-601
Open Redirect
|
CVE-2016-10742
|
2024-11-21 11:44 |
2019-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265850
|
4.7 |
MEDIUM
Local
|
linux debian
|
linux_kernel debian_linux
|
In the Linux kernel before 4.9.3, fs/xfs/xfs_aops.c allows local users to cause a denial of service (system crash) because there is a race condition between direct and memory-mapped I/O (associated w…
|
CWE-362
Race Condition
|
CVE-2016-10741
|
2024-11-21 11:44 |
2019-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|