|
266341
|
5.5 |
MEDIUM
Local
|
artifex
|
ghostscript
|
The pdf14_open function in base/gdevp14.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted file tha…
|
CWE-416
Use After Free
|
CVE-2016-10217
|
2024-11-21 11:43 |
2017-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266342
|
7.5 |
HIGH
Network
|
virustotal
|
yara
|
libyara/grammar.y in YARA 3.5.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted rule that is mishandled in the yr_parser_lookup_loop_variable…
|
CWE-416
Use After Free
|
CVE-2016-10211
|
2024-11-21 11:43 |
2017-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266343
|
7.5 |
HIGH
Network
|
virustotal
|
yara
|
libyara/lexer.l in YARA 3.5.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted rule that is mishandled in the yy_get_next_buffer fun…
|
CWE-476
NULL Pointer Dereference
|
CVE-2016-10210
|
2024-11-21 11:43 |
2017-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266344
|
5.5 |
MEDIUM
Local
|
libarchive
|
libarchive
|
The archive_wstring_append_from_mbs function in archive_string.c in libarchive 3.2.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafte…
|
CWE-476
NULL Pointer Dereference
|
CVE-2016-10209
|
2024-11-21 11:43 |
2017-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266345
|
9.8 |
CRITICAL
Network
|
ceragon
|
fibeair_ip-10_firmware
|
In the GUI of Ceragon FibeAir IP-10 (before 7.2.0) devices, a remote attacker can bypass authentication by adding an ALBATROSS cookie with the value 0-4-11 to their browser.
|
CWE-287
Improper Authentication
|
CVE-2016-10309
|
2024-11-21 11:43 |
2017-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266346
|
9.8 |
CRITICAL
Network
|
siklu
|
etherhaul_firmware
|
Siklu EtherHaul radios before 3.7.1 and 6.x before 6.9.0 have a built-in, hidden root account, with an unchangeable password that is the same across all devices. This account is accessible via both S…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2016-10308
|
2024-11-21 11:43 |
2017-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266347
|
9.8 |
CRITICAL
Network
|
gotrango
|
apex_lynx_firmware apex_orion_firmware giga_lynx_firmware giga_orion_firmware stratalink_firmware
|
Trango ApexLynx 2.0, ApexOrion 2.0, GigaLynx 2.0, GigaOrion 2.0, and StrataLink 3.0 devices have a built-in, hidden root account, with a default password for which the MD5 hash value is public (but t…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2016-10307
|
2024-11-21 11:43 |
2017-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266348
|
9.8 |
CRITICAL
Network
|
trango
|
a600_firmware
|
Trango Altum AC600 devices have a built-in, hidden root account, with a default password of abcd1234. This account is accessible via SSH and/or TELNET, and grants access to the underlying embedded UN…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2016-10306
|
2024-11-21 11:43 |
2017-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266349
|
9.8 |
CRITICAL
Network
|
gotrango
|
apex_plus_firmware apex_firmware apex_lynx_firmware apex_orion_firmware giga_firmware giga_lynx_firmware giga_orion_firmware giga_plus_firmware giga_pro_firmware stratalink…
|
Trango Apex <= 2.1.1, ApexLynx < 2.0, ApexOrion < 2.0, ApexPlus <= 3.2.0, Giga <= 2.6.1, GigaLynx < 2.0, GigaOrion < 2.0, GigaPlus <= 3.2.3, GigaPro <= 1.4.1, StrataLink < 3.0, and StrataPro devices …
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2016-10305
|
2024-11-21 11:43 |
2017-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266350
|
9.8 |
CRITICAL
Network
|
hesiod_project
|
hesiod
|
The read_config_file function in lib/hesiod.c in Hesiod 3.2.1 falls back to the ".athena.mit.edu" default domain when opening the configuration file fails, which allows remote attackers to gain root …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-10152
|
2024-11-21 11:43 |
2017-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|