|
266021
|
5.5 |
MEDIUM
Local
|
artifex
|
ghostscript
|
The gs_makewordimagedevice function in base/gsdevmem.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash)…
|
CWE-476
NULL Pointer Dereference
|
CVE-2016-10220
|
2024-11-21 11:43 |
2017-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266022
|
5.5 |
MEDIUM
Local
|
artifex
|
ghostscript
|
The intersect function in base/gxfill.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted file.
|
CWE-369
Divide By Zero
|
CVE-2016-10219
|
2024-11-21 11:43 |
2017-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266023
|
5.5 |
MEDIUM
Local
|
artifex
|
ghostscript
|
The pdf14_pop_transparency_group function in base/gdevp14.c in the PDF Transparency module in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (NULL pointe…
|
CWE-476
NULL Pointer Dereference
|
CVE-2016-10218
|
2024-11-21 11:43 |
2017-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266024
|
5.5 |
MEDIUM
Local
|
artifex
|
ghostscript
|
The pdf14_open function in base/gdevp14.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted file tha…
|
CWE-416
Use After Free
|
CVE-2016-10217
|
2024-11-21 11:43 |
2017-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266025
|
7.5 |
HIGH
Network
|
virustotal
|
yara
|
libyara/grammar.y in YARA 3.5.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted rule that is mishandled in the yr_parser_lookup_loop_variable…
|
CWE-416
Use After Free
|
CVE-2016-10211
|
2024-11-21 11:43 |
2017-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266026
|
7.5 |
HIGH
Network
|
virustotal
|
yara
|
libyara/lexer.l in YARA 3.5.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted rule that is mishandled in the yy_get_next_buffer fun…
|
CWE-476
NULL Pointer Dereference
|
CVE-2016-10210
|
2024-11-21 11:43 |
2017-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266027
|
5.5 |
MEDIUM
Local
|
libarchive
|
libarchive
|
The archive_wstring_append_from_mbs function in archive_string.c in libarchive 3.2.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafte…
|
CWE-476
NULL Pointer Dereference
|
CVE-2016-10209
|
2024-11-21 11:43 |
2017-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266028
|
9.8 |
CRITICAL
Network
|
ceragon
|
fibeair_ip-10_firmware
|
In the GUI of Ceragon FibeAir IP-10 (before 7.2.0) devices, a remote attacker can bypass authentication by adding an ALBATROSS cookie with the value 0-4-11 to their browser.
|
CWE-287
Improper Authentication
|
CVE-2016-10309
|
2024-11-21 11:43 |
2017-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266029
|
9.8 |
CRITICAL
Network
|
siklu
|
etherhaul_firmware
|
Siklu EtherHaul radios before 3.7.1 and 6.x before 6.9.0 have a built-in, hidden root account, with an unchangeable password that is the same across all devices. This account is accessible via both S…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2016-10308
|
2024-11-21 11:43 |
2017-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266030
|
9.8 |
CRITICAL
Network
|
gotrango
|
apex_lynx_firmware apex_orion_firmware giga_lynx_firmware giga_orion_firmware stratalink_firmware
|
Trango ApexLynx 2.0, ApexOrion 2.0, GigaLynx 2.0, GigaOrion 2.0, and StrataLink 3.0 devices have a built-in, hidden root account, with a default password for which the MD5 hash value is public (but t…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2016-10307
|
2024-11-21 11:43 |
2017-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|