|
265701
|
8.8 |
HIGH
Network
|
google debian opensuse
|
chrome debian_linux opensuse
|
The Extensions subsystem in Google Chrome before 48.0.2564.109 does not prevent use of the Object.defineProperty method to override intended extension behavior, which allows remote attackers to bypas…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-1622
|
2024-11-21 11:46 |
2016-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265702
|
8.1 |
HIGH
Network
|
debian mozilla sil fedoraproject
|
debian_linux firefox thunderbird graphite2 fedora
|
The TtfUtil:LocaLookup function in TtfUtil.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, incorrectly validates a size value, which…
|
CWE-119 CWE-200
Incorrect Access of Indexable Resource ('Range Error') Information Exposure
|
CVE-2016-1526
|
2024-11-21 11:46 |
2016-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265703
|
8.6 |
HIGH
Network
|
netgear
|
prosafe_network_management_software_300
|
Directory traversal vulnerability in data/config/image.do in NETGEAR Management System NMS300 1.5.0.11 and earlier allows remote authenticated users to read arbitrary files via a .. (dot dot) in the …
|
CWE-22
Path Traversal
|
CVE-2016-1525
|
2024-11-21 11:46 |
2016-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265704
|
9.6 |
CRITICAL
Adjacent
|
netgear
|
prosafe_network_management_software_300
|
Multiple unrestricted file upload vulnerabilities in NETGEAR Management System NMS300 1.5.0.11 and earlier allow remote attackers to execute arbitrary Java code by using (1) fileUpload.do or (2) lib-…
|
NVD-CWE-Other
|
CVE-2016-1524
|
2024-11-21 11:46 |
2016-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265705
|
6.5 |
MEDIUM
Network
|
fedoraproject mozilla sil debian
|
fedora firefox thunderbird graphite2 debian_linux
|
The SillMap::readFace function in FeatureMap.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, mishandles a return value, which allows…
|
NVD-CWE-Other
|
CVE-2016-1523
|
2024-11-21 11:46 |
2016-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265706
|
8.8 |
HIGH
Network
|
fedoraproject mozilla debian sil
|
fedora firefox thunderbird debian_linux graphite2
|
Code.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, does not consider recursive load calls during a size check, which allows remote…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-1522
|
2024-11-21 11:46 |
2016-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265707
|
8.8 |
HIGH
Network
|
debian sil mozilla fedoraproject
|
debian_linux graphite2 firefox thunderbird fedora
|
The directrun function in directmachine.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, does not validate a certain skip operation, …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-1521
|
2024-11-21 11:46 |
2016-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265708
|
5.3 |
MEDIUM
Network
|
cisco
|
spark
|
The REST interface in Cisco Spark 2015-06 allows remote attackers to cause a denial of service (resource outage) by accessing an administrative page, aka Bug ID CSCuv84125.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-1324
|
2024-11-21 11:46 |
2016-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265709
|
4.3 |
MEDIUM
Network
|
cisco
|
spark
|
The REST interface in Cisco Spark 2015-06 allows remote authenticated users to obtain sensitive information via a request for an unspecified file, aka Bug ID CSCuv84048.
|
CWE-200
Information Exposure
|
CVE-2016-1323
|
2024-11-21 11:46 |
2016-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265710
|
7.5 |
HIGH
Network
|
cisco
|
spark
|
The REST interface in Cisco Spark 2015-07-04 allows remote attackers to bypass intended access restrictions and create arbitrary user accounts via unspecified web requests, aka Bug ID CSCuv72584.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-1322
|
2024-11-21 11:46 |
2016-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|