|
266311
|
7.8 |
HIGH
Local
|
firejail_project
|
firejail
|
Firejail does not properly clean environment variables, which allows local users to gain privileges.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-10122
|
2024-11-21 11:43 |
2017-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266312
|
7.8 |
HIGH
Local
|
firejail_project
|
firejail
|
Firejail uses weak permissions for /dev/shm/firejail and possibly other files, which allows local users to gain privileges.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-10121
|
2024-11-21 11:43 |
2017-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266313
|
7.8 |
HIGH
Local
|
firejail_project
|
firejail
|
Firejail uses 0777 permissions when mounting (1) /dev, (2) /dev/shm, (3) /var/tmp, or (4) /var/lock, which allows local users to gain privileges.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-10120
|
2024-11-21 11:43 |
2017-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266314
|
7.8 |
HIGH
Local
|
firejail_project
|
firejail
|
Firejail uses 0777 permissions when mounting /tmp, which allows local users to gain privileges.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-10119
|
2024-11-21 11:43 |
2017-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266315
|
3.3 |
LOW
Local
|
firejail_project
|
firejail
|
Firejail allows local users to truncate /etc/resolv.conf via a chroot command to /.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-10118
|
2024-11-21 11:43 |
2017-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266316
|
7.8 |
HIGH
Local
|
firejail_project
|
firejail
|
Firejail does not restrict access to --tmpfs, which allows local users to gain privileges, as demonstrated by mounting over /etc.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-10117
|
2024-11-21 11:43 |
2017-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266317
|
5.9 |
MEDIUM
Network
|
bluecoat
|
ssl_visibility_appliance_sv1800_firmware ssl_visibility_appliance_sv800_firmware ssl_visibility_appliance_sv3800_firmware ssl_visibility_appliance_sv2800_firmware
|
Symantec SSL Visibility (SSLV) 3.8.4FC, 3.9, 3.10 before 3.10.4.1, and 3.11 before 3.11.3.1 is susceptible to a denial-of-service vulnerability that impacts the SSL servers for intercepted SSL connec…
|
CWE-399
Resource Management Errors
|
CVE-2016-10259
|
2024-11-21 11:43 |
2017-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266318
|
7.8 |
HIGH
Local
|
synology
|
photo_station
|
Synology Photo Station before 6.3-2958 allows local users to gain privileges by leveraging setuid execution of a "synophoto_dsm_user --copy-no-ea" command.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-10323
|
2024-11-21 11:43 |
2017-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266319
|
8.8 |
HIGH
Network
|
synology
|
photo_station
|
Synology Photo Station before 6.3-2958 allows remote authenticated guest users to execute arbitrary commands via shell metacharacters in the X-Forwarded-For HTTP header to photo/login.php.
|
CWE-77
Command Injection
|
CVE-2016-10322
|
2024-11-21 11:43 |
2017-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266320
|
9.8 |
CRITICAL
Network
|
sap
|
netweaver
|
Stack-based buffer overflow in SAP NetWeaver 7.0 through 7.5 allows remote attackers to cause a denial of service () by sending a crafted packet to the SAPSTARTSRV port, aka SAP Security Note 2295238.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-10311
|
2024-11-21 11:43 |
2017-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|