|
266161
|
9.8 |
CRITICAL
Network
|
dlink
|
dwr-932b_firmware
|
An issue was discovered on the D-Link DWR-932B router. HELODBG on port 39889 (UDP) launches the "/sbin/telnetd -l /bin/sh" command.
|
CWE-254
7PK - Security Features
|
CVE-2016-10178
|
2024-11-21 11:43 |
2017-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266162
|
9.8 |
CRITICAL
Network
|
dlink
|
dwr-932b_firmware
|
An issue was discovered on the D-Link DWR-932B router. Undocumented TELNET and SSH services provide logins to admin with the password admin and root with the password 1234.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2016-10177
|
2024-11-21 11:43 |
2017-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266163
|
9.8 |
CRITICAL
Network
|
netgear
|
wnr2000v5_firmware
|
The NETGEAR WNR2000v5 router leaks its serial number when performing a request to the /BRS_netgear_success.html URI. This serial number allows a user to obtain the administrator username and password…
|
CWE-200
Information Exposure
|
CVE-2016-10175
|
2024-11-21 11:43 |
2017-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266164
|
9.8 |
CRITICAL
Network
|
netgear
|
wnr2000v5_firmware
|
The NETGEAR WNR2000v5 router allows an administrator to perform sensitive actions by invoking the apply.cgi URL on the web server of the device. This special URL is handled by the embedded web server…
|
CWE-20
Improper Input Validation
|
CVE-2016-10176
|
2024-11-21 11:43 |
2017-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266165
|
7.5 |
HIGH
Network
|
squid-cache
|
squid
|
Incorrect HTTP Request header comparison in Squid HTTP Proxy 3.5.0.1 through 3.5.22, and 4.0.1 through 4.0.16 results in Collapsed Forwarding feature mistakenly identifying some private responses as …
|
CWE-697
Incorrect Comparison
|
CVE-2016-10003
|
2024-11-21 11:43 |
2017-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266166
|
7.5 |
HIGH
Network
|
debian squid-cache
|
debian_linux squid
|
Incorrect processing of responses to If-None-Modified HTTP conditional requests in Squid HTTP Proxy 3.1.10 through 3.1.23, 3.2.0.3 through 3.5.22, and 4.0.1 through 4.0.16 leads to client-specific Co…
|
CWE-200
Information Exposure
|
CVE-2016-10002
|
2024-11-21 11:43 |
2017-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266167
|
5.5 |
MEDIUM
Local
|
xen citrix
|
xen xenserver
|
VMFUNC emulation in Xen 4.6.x through 4.8.x on x86 systems using AMD virtualization extensions (aka SVM) allows local HVM guest OS users to cause a denial of service (hypervisor crash) by leveraging …
|
CWE-476
NULL Pointer Dereference
|
CVE-2016-10025
|
2024-11-21 11:43 |
2017-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266168
|
6.0 |
MEDIUM
Local
|
xen citrix
|
xen xenserver
|
Xen through 4.8.x allows local x86 PV guest OS kernel administrators to cause a denial of service (host hang or crash) by modifying the instruction stream asynchronously while performing certain kern…
|
CWE-20
Improper Input Validation
|
CVE-2016-10024
|
2024-11-21 11:43 |
2017-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266169
|
7.8 |
HIGH
Local
|
xen
|
xen
|
Xen through 4.8.x allows local 64-bit x86 HVM guest OS users to gain privileges by leveraging mishandling of SYSCALL singlestep during emulation.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-10013
|
2024-11-21 11:43 |
2017-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266170
|
7.5 |
HIGH
Network
|
php
|
php
|
The php_wddx_pop_element function in ext/wddx/wddx.c in PHP 7.0.x before 7.0.15 and 7.1.x before 7.1.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application c…
|
CWE-476
NULL Pointer Dereference
|
CVE-2016-10162
|
2024-11-21 11:43 |
2017-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|