|
266151
|
10.0 |
CRITICAL
Network
|
mrf
|
web_panel
|
An issue was discovered in Radisys MRF Web Panel (SWMS) 9.0.1. The MSM_MACRO_NAME POST parameter in /swms/ms.cgi was discovered to be vulnerable to OS command injection attacks. It is possible to use…
|
CWE-78
OS Command
|
CVE-2016-10043
|
2024-11-21 11:43 |
2017-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266152
|
7.5 |
HIGH
Network
|
libpng
|
libpng
|
The png_set_text_2 function in libpng 0.71 before 1.0.67, 1.2.x before 1.2.57, 1.4.x before 1.4.20, 1.5.x before 1.5.28, and 1.6.x before 1.6.27 allows context-dependent attackers to cause a NULL poi…
|
CWE-476
NULL Pointer Dereference
|
CVE-2016-10087
|
2024-11-21 11:43 |
2017-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266153
|
7.5 |
HIGH
Network
|
dlink
|
dwr-932b_firmware
|
An issue was discovered on the D-Link DWR-932B router. /var/miniupnpd.conf has no deny rules.
|
CWE-399
Resource Management Errors
|
CVE-2016-10186
|
2024-11-21 11:43 |
2017-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266154
|
7.5 |
HIGH
Network
|
dlink
|
dwr-932b_firmware
|
An issue was discovered on the D-Link DWR-932B router. A secure_mode=no line exists in /var/miniupnpd.conf.
|
CWE-254
7PK - Security Features
|
CVE-2016-10185
|
2024-11-21 11:43 |
2017-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266155
|
7.5 |
HIGH
Network
|
dlink
|
dwr-932b_firmware
|
An issue was discovered on the D-Link DWR-932B router. qmiweb allows file reading with ..%2f traversal.
|
CWE-22
Path Traversal
|
CVE-2016-10184
|
2024-11-21 11:43 |
2017-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266156
|
7.5 |
HIGH
Network
|
dlink
|
dwr-932b_firmware
|
An issue was discovered on the D-Link DWR-932B router. qmiweb allows directory listing with ../ traversal.
|
CWE-22
Path Traversal
|
CVE-2016-10183
|
2024-11-21 11:43 |
2017-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266157
|
9.8 |
CRITICAL
Network
|
dlink
|
dwr-932b_firmware
|
An issue was discovered on the D-Link DWR-932B router. qmiweb allows command injection with ` characters.
|
CWE-77
Command Injection
|
CVE-2016-10182
|
2024-11-21 11:43 |
2017-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266158
|
7.5 |
HIGH
Network
|
dlink
|
dwr-932b_firmware
|
An issue was discovered on the D-Link DWR-932B router. qmiweb provides sensitive information for CfgType=get_homeCfg requests.
|
CWE-200
Information Exposure
|
CVE-2016-10181
|
2024-11-21 11:43 |
2017-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266159
|
7.5 |
HIGH
Network
|
dlink
|
dwr-932b_firmware
|
An issue was discovered on the D-Link DWR-932B router. WPS PIN generation is based on srand(time(0)) seeding.
|
CWE-335
Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG)
|
CVE-2016-10180
|
2024-11-21 11:43 |
2017-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266160
|
7.5 |
HIGH
Network
|
dlink
|
dwr-932b_firmware
|
An issue was discovered on the D-Link DWR-932B router. There is a hardcoded WPS PIN of 28296607.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2016-10179
|
2024-11-21 11:43 |
2017-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|