|
266201
|
6.1 |
MEDIUM
Network
|
sap
|
netweaver
|
Multiple cross-site scripting (XSS) vulnerabilities in SAP NetWeaver 7.4 allow remote attackers to inject arbitrary web script or HTML via vectors related to the (1) Runtime Workbench (RWB) or (2) Pm…
|
CWE-79
Cross-site Scripting
|
CVE-2016-1911
|
2024-11-21 11:47 |
2016-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266202
|
5.3 |
MEDIUM
Network
|
sap
|
netweaver
|
The User Management Engine (UME) in SAP NetWeaver 7.4 allows attackers to decrypt unspecified data via unknown vectors, aka SAP Security Note 2191290.
|
CWE-200
Information Exposure
|
CVE-2016-1910
|
2024-11-21 11:47 |
2016-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266203
|
9.8 |
CRITICAL
Network
|
fortinet
|
fortios
|
Fortinet FortiAnalyzer before 5.0.12 and 5.2.x before 5.2.5; FortiSwitch 3.3.x before 3.3.3; FortiCache 3.0.x before 3.0.8; and FortiOS 4.1.x before 4.1.11, 4.2.x before 4.2.16, 4.3.x before 4.3.17 a…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-1909
|
2024-11-21 11:47 |
2016-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266204
|
5.5 |
MEDIUM
Local
|
ffmpeg canonical opensuse
|
ffmpeg ubuntu_linux leap
|
FFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using the subfile protocol in an HTTP Live Streaming (HLS) M3U8 file, leading to an external HTTP reques…
|
CWE-200
Information Exposure
|
CVE-2016-1898
|
2024-11-21 11:47 |
2016-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266205
|
5.5 |
MEDIUM
Local
|
ffmpeg canonical opensuse
|
ffmpeg ubuntu_linux leap
|
FFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using the concat protocol in an HTTP Live Streaming (HLS) M3U8 file, leading to an external HTTP request…
|
CWE-200
Information Exposure
|
CVE-2016-1897
|
2024-11-21 11:47 |
2016-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266206
|
9.8 |
CRITICAL
Network
|
debian
|
duck
|
duck before 0.10 did not properly handle loading of untrusted code from the current directory.
|
NVD-CWE-noinfo
|
CVE-2016-1239
|
2024-11-21 11:46 |
2022-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266207
|
8.8 |
HIGH
Network
|
lexmark
|
markvision_enterprise
|
Lexmark Markvision Enterprise before 2.3.0 misuses the Apache Commons Collections Library, leading to remote code execution because of Java deserialization.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2016-1487
|
2024-11-21 11:46 |
2020-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266208
|
3.3 |
LOW
Local
|
nghttp2 fedoraproject
|
nghttp2 fedora
|
nghttp2 before 1.7.1 allows remote attackers to cause a denial of service (memory exhaustion).
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2016-1544
|
2024-11-21 11:46 |
2020-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266209
|
7.5 |
HIGH
Network
|
microfocus
|
identity_manager
|
The ServiceNow driver in NetIQ Identity Manager versions prior to 4.6 are susceptible to an information disclosure vulnerability.
|
CWE-200
Information Exposure
|
CVE-2016-1600
|
2024-11-21 11:46 |
2019-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266210
|
7.5 |
HIGH
Network
|
snapweb
|
snapweb
|
The Snapweb interface before version 0.21.2 was exposing controls to install or remove snap packages without controlling the identity of the user, nor the origin of the connection. An attacker could …
|
CWE-284
Improper Access Control
|
CVE-2016-1587
|
2024-11-21 11:46 |
2019-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|