|
266221
|
9.8 |
CRITICAL
Network
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, the UE can send unprotected MeasurementReports revealing UE location.
|
CWE-1
Location
|
CVE-2016-10380
|
2024-11-21 11:43 |
2017-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266222
|
9.8 |
CRITICAL
Network
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, an argument to a hypervisor function is not properly validated.
|
CWE-20
Improper Input Validation
|
CVE-2016-10347
|
2024-11-21 11:43 |
2017-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266223
|
9.8 |
CRITICAL
Network
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, an integer overflow vulnerability exists in the hypervisor.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2016-10346
|
2024-11-21 11:43 |
2017-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266224
|
9.8 |
CRITICAL
Network
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, the use of an out-of-range pointer offset is potentially possible in LTE.
|
CWE-476
NULL Pointer Dereference
|
CVE-2016-10344
|
2024-11-21 11:43 |
2017-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266225
|
9.8 |
CRITICAL
Network
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, sSL handshake failure with ClientHello rejection results in memory leak.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-10343
|
2024-11-21 11:43 |
2017-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266226
|
6.1 |
MEDIUM
Network
|
liferay
|
liferay_portal
|
XSS exists in Liferay Portal before 7.0 CE GA4 via a crafted redirect field to modules/apps/foundation/frontend-js/frontend-js-spa-web/src/main/resources/META-INF/resources/init.jsp.
|
CWE-79
Cross-site Scripting
|
CVE-2016-10404
|
2024-11-21 11:43 |
2017-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266227
|
7.5 |
HIGH
Network
|
sendio
|
sendio
|
Sendio versions before 8.2.1 were affected by a Local File Inclusion vulnerability that allowed an unauthenticated, remote attacker to read potentially sensitive system files via a specially crafted …
|
CWE-538
File and Directory Information Exposure
|
CVE-2016-10399
|
2024-11-21 11:43 |
2017-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266228
|
7.8 |
HIGH
Local
|
avira
|
antivirus
|
Avira Antivirus engine versions before 8.3.36.60 allow remote code execution as NT AUTHORITY\SYSTEM via a section header with a very large relative virtual address in a PE file, causing an integer ov…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-10402
|
2024-11-21 11:43 |
2017-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266229
|
8.8 |
HIGH
Network
|
zyxel
|
pk5001z_firmware
|
ZyXEL PK5001Z devices have zyad5001 as the su password, which makes it easier for remote attackers to obtain root access if a non-root account password is known (or a non-root default account exists …
|
CWE-255
Credentials Management
|
CVE-2016-10401
|
2024-11-21 11:43 |
2017-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266230
|
7.5 |
HIGH
Network
|
atutor
|
atutor
|
Directory Traversal exists in ATutor before 2.2.2 via the icon parameter to /mods/_core/courses/users/create_course.php. The attacker can read an arbitrary file by visiting get_course_icon.php?id= af…
|
CWE-22
Path Traversal
|
CVE-2016-10400
|
2024-11-21 11:43 |
2017-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|