|
266231
|
6.2 |
MEDIUM
Physics
|
google
|
android
|
Android 6.0 has an authentication bypass for attackers with root and physical access. Cryptographic authentication tokens (AuthTokens) used by the Trusted Execution Environment (TEE) are protected by…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-10398
|
2024-11-21 11:43 |
2017-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266232
|
7.5 |
HIGH
Network
|
php
|
php
|
In PHP before 5.6.28 and 7.x before 7.0.13, incorrect handling of various URI components in the URL parser could be used by attackers to bypass hostname-specific URL checks, as demonstrated by evil.e…
|
CWE-20
Improper Input Validation
|
CVE-2016-10397
|
2024-11-21 11:43 |
2017-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266233
|
7.5 |
HIGH
Network
|
ipsec-tools
|
ipsec-tools
|
The racoon daemon in IPsec-Tools 0.8.2 contains a remotely exploitable computational-complexity attack when parsing and storing ISAKMP fragments. The implementation permits a remote attacker to exhau…
|
CWE-407
Inefficient Algorithmic Complexity
|
CVE-2016-10396
|
2024-11-21 11:43 |
2017-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266234
|
7.5 |
HIGH
Network
|
arcadyan
|
swisscom_internet-box_firmware
|
Authorization Bypass in the Web interface of Arcadyan SLT-00 Star* (aka Swisscom Internet-Box) devices before R7.7 allows unauthorized reconfiguration of the static routing table via an unauthenticat…
|
CWE-284
Improper Access Control
|
CVE-2016-10042
|
2024-11-21 11:43 |
2017-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266235
|
6.1 |
MEDIUM
Network
|
elastic
|
kibana
|
Kibana versions after and including 4.3 and before 4.6.2 are vulnerable to a cross-site scripting (XSS) attack.
|
CWE-79
Cross-site Scripting
|
CVE-2016-10366
|
2024-11-21 11:43 |
2017-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266236
|
6.1 |
MEDIUM
Network
|
elastic
|
kibana
|
Kibana versions before 4.6.3 and 5.0.1 have an open redirect vulnerability that would enable an attacker to craft a link in the Kibana domain that redirects to an arbitrary website.
|
CWE-601
Open Redirect
|
CVE-2016-10365
|
2024-11-21 11:43 |
2017-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266237
|
6.5 |
MEDIUM
Network
|
elastic
|
kibana
|
With X-Pack installed, Kibana versions 5.0.0 and 5.0.1 were not properly authenticating requests to advanced settings and the short URL service, any authenticated user could make requests to those se…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-10364
|
2024-11-21 11:43 |
2017-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266238
|
7.5 |
HIGH
Network
|
elastic
|
logstash
|
Logstash versions prior to 2.3.3, when using the Netflow Codec plugin, a remote attacker crafting malicious Netflow v5, Netflow v9 or IPFIX packets could perform a denial of service attack on the Log…
|
CWE-404
Improper Resource Shutdown or Release
|
CVE-2016-10363
|
2024-11-21 11:43 |
2017-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266239
|
6.5 |
MEDIUM
Network
|
elasticsearch
|
output_plugin
|
Prior to Logstash version 5.0.1, Elasticsearch Output plugin when updating connections after sniffing, would log to file HTTP basic auth credentials.
|
CWE-200
Information Exposure
|
CVE-2016-10362
|
2024-11-21 11:43 |
2017-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266240
|
7.5 |
HIGH
Network
|
elastic
|
logstash
|
Logstash prior to version 2.1.2, the CSV output can be attacked via engineered input that will create malicious formulas in the CSV data.
|
CWE-88
Argument Injection
|
CVE-2016-1000222
|
2024-11-21 11:43 |
2017-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|