|
265651
|
9.8 |
CRITICAL
Network
|
debian
|
most
|
The most package in Debian wheezy before 5.0.0a-2.2, in Debian jessie before 5.0.0a-2.3+deb8u1, and in Debian unstable before 5.0.0a-3 allows remote attackers to execute arbitrary commands via shell …
|
CWE-78
OS Command
|
CVE-2016-1253
|
2024-11-21 11:46 |
2017-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265652
|
5.9 |
MEDIUM
Network
|
debian canonical
|
advanced_package_tool ubuntu_linux
|
The apt package in Debian jessie before 1.0.9.8.4, in Debian unstable before 1.4~beta2, in Ubuntu 14.04 LTS before 1.0.1ubuntu2.17, in Ubuntu 16.04 LTS before 1.2.15ubuntu0.2, and in Ubuntu 16.10 bef…
|
CWE-295
Improper Certificate Validation
|
CVE-2016-1252
|
2024-11-21 11:46 |
2017-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265653
|
9.8 |
CRITICAL
Network
|
juniper
|
junos_space
|
A remote unauthenticated network based attacker with access to Junos Space may execute arbitrary code on Junos Space or gain access to devices managed by Junos Space using cross site request forgery …
|
CWE-255 CWE-352 CWE-200
Credentials Management Origin Validation Error Information Exposure
|
CVE-2016-1265
|
2024-11-21 11:46 |
2017-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265654
|
8.8 |
HIGH
Network
|
juniper
|
junos
|
J-Web does not validate certain input that may lead to cross-site request forgery (CSRF) issues or cause a denial of J-Web service (DoS).
|
CWE-352
Origin Validation Error
|
CVE-2016-1261
|
2024-11-21 11:46 |
2017-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265655
|
7.5 |
HIGH
Network
|
exagrid
|
ex3000_firmware ex5000_firmware ex7000_firmware ex10000e_firmware ex13000e_firmware ex21000e_firmware ex32000e_firmware ex40000e_firmware
|
ExaGrid appliances with firmware before 4.8 P26 have a default SSH public key in the authorized_keys file for root, which allows remote attackers to obtain SSH access by leveraging knowledge of a pri…
|
CWE-200
Information Exposure
|
CVE-2016-1561
|
2024-11-21 11:46 |
2017-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265656
|
9.8 |
CRITICAL
Network
|
exagrid
|
ex3000_firmware ex5000_firmware ex7000_firmware ex10000e_firmware ex13000e_firmware ex21000e_firmware ex32000e_firmware ex40000e_firmware
|
ExaGrid appliances with firmware before 4.8 P26 have a default password of (1) inflection for the root shell account and (2) support for the support account in the web interface, which allows remote …
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2016-1560
|
2024-11-21 11:46 |
2017-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265657
|
7.8 |
HIGH
Local
|
grandstream
|
wave
|
The Grandstream Wave app 1.0.1.26 and earlier for Android does not use HTTPS when retrieving update information, which might allow man-in-the-middle attackers to execute arbitrary code via a crafted …
|
CWE-254
7PK - Security Features
|
CVE-2016-1520
|
2024-11-21 11:46 |
2017-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265658
|
5.9 |
MEDIUM
Network
|
grandstream
|
wave
|
The com.softphone.common package in the Grandstream Wave app 1.0.1.26 and earlier for Android does not properly validate SSL certificates, which allows man-in-the-middle attackers to spoof the Grands…
|
CWE-295
Improper Certificate Validation
|
CVE-2016-1519
|
2024-11-21 11:46 |
2017-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265659
|
8.1 |
HIGH
Network
|
grandstream
|
wave
|
The auto-provisioning mechanism in the Grandstream Wave app 1.0.1.26 and earlier for Android and Grandstream Video IP phones allows man-in-the-middle attackers to spoof provisioning data and conseque…
|
CWE-284
Improper Access Control
|
CVE-2016-1518
|
2024-11-21 11:46 |
2017-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265660
|
8.1 |
HIGH
Network
|
d-link
|
dap-1353_h\/w_b1_firmware dap-2553_h\/w_a1_firmware dap-3520_h\/w_a1_firmware
|
D-Link DAP-1353 H/W vers. B1 3.15 and earlier, D-Link DAP-2553 H/W ver. A1 1.31 and earlier, and D-Link DAP-3520 H/W ver. A1 1.16 and earlier reveal wireless passwords and administrative usernames an…
|
CWE-200
Information Exposure
|
CVE-2016-1559
|
2024-11-21 11:46 |
2017-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|