|
265611
|
6.1 |
MEDIUM
Network
|
cisco
|
unity_connection
|
Cross-site scripting (XSS) vulnerability in Cisco Unity Connection through 11.0 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCus21776.
|
CWE-79
Cross-site Scripting
|
CVE-2016-1377
|
2024-11-21 11:46 |
2016-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265612
|
5.3 |
MEDIUM
Network
|
cisco
|
ios_xr
|
Cisco IOS XR 4.2.3, 4.3.0, 4.3.4, and 5.3.1 on ASR 9000 devices allows remote attackers to cause a denial of service (CRC and symbol errors, and interface flap) via crafted bit patterns in packets, a…
|
CWE-20
Improper Input Validation
|
CVE-2016-1376
|
2024-11-21 11:46 |
2016-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265613
|
8.8 |
HIGH
Local
|
qemu redhat debian
|
qemu openstack virtualization debian_linux
|
Use-after-free vulnerability in hw/ide/ahci.c in QEMU, when built with IDE AHCI Emulation support, allows guest OS users to cause a denial of service (instance crash) or possibly execute arbitrary co…
|
CWE-416
Use After Free
|
CVE-2016-1568
|
2024-11-21 11:46 |
2016-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265614
|
8.8 |
HIGH
Network
|
oar_project debian
|
oar debian_linux
|
The oarsh script in OAR before 2.5.7 allows remote authenticated users of a cluster to obtain sensitive information and possibly gain privileges via vectors related to OpenSSH options.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-1235
|
2024-11-21 11:46 |
2016-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265615
|
6.1 |
MEDIUM
Network
|
cisco
|
ip_interoperability_and_collaboration_system
|
Cross-site scripting (XSS) vulnerability in Cisco IP Interoperability and Collaboration System 4.10(1) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSC…
|
CWE-79
Cross-site Scripting
|
CVE-2016-1375
|
2024-11-21 11:46 |
2016-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265616
|
7.0 |
HIGH
Local
|
exim
|
exim
|
Exim before 4.86.2, when installed setuid root, allows local users to gain privileges via the perl_startup argument.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-1531
|
2024-11-21 11:46 |
2016-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265617
|
8.1 |
HIGH
Local
|
redhat oracle qemu
|
openstack linux qemu
|
The (1) fw_cfg_write and (2) fw_cfg_read functions in hw/nvram/fw_cfg.c in QEMU before 2.4, when built with the Firmware Configuration device emulation support, allow guest OS users with the CAP_SYS_…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-1714
|
2024-11-21 11:46 |
2016-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265618
|
6.8 |
MEDIUM
Network
|
netapp
|
clustered_data_ontap
|
NetApp Clustered Data ONTAP 8.3.1 does not properly verify X.509 certificates from TLS servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafte…
|
CWE-200 CWE-20
Information Exposure Improper Input Validation
|
CVE-2016-1563
|
2024-11-21 11:46 |
2016-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265619
|
5.9 |
MEDIUM
Network
|
dell netgear samsung zyxel zzinc
|
emc_powerscale_onefs jr6150_firmware x14j_firmware gs1900-10hp_firmware keymouse_firmware
|
The kernel in Cisco TelePresence Server 3.0 through 4.2(4.18) on Mobility Services Engine (MSE) 8710 devices allows remote attackers to cause a denial of service (panic and reboot) via a crafted sequ…
|
CWE-399
Resource Management Errors
|
CVE-2016-1346
|
2024-11-21 11:46 |
2016-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265620
|
9.8 |
CRITICAL
Network
|
cisco
|
ucs_invicta_c3124sa_appliance
|
Cisco UCS Invicta C3124SA Appliance 4.3.1 through 5.0.1, UCS Invicta Scaling System and Appliance, and Whiptail Racerunner improperly store a default SSH private key, which allows remote attackers to…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-1313
|
2024-11-21 11:46 |
2016-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|