|
267641
|
9.8 |
CRITICAL
Network
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, the UE can send unprotected MeasurementReports revealing UE location.
|
CWE-1
Location
|
CVE-2016-10381
|
2024-11-21 11:43 |
2017-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267642
|
9.8 |
CRITICAL
Network
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, the UE can send unprotected MeasurementReports revealing UE location.
|
CWE-1
Location
|
CVE-2016-10380
|
2024-11-21 11:43 |
2017-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267643
|
9.8 |
CRITICAL
Network
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, an argument to a hypervisor function is not properly validated.
|
CWE-20
Improper Input Validation
|
CVE-2016-10347
|
2024-11-21 11:43 |
2017-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267644
|
9.8 |
CRITICAL
Network
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, an integer overflow vulnerability exists in the hypervisor.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2016-10346
|
2024-11-21 11:43 |
2017-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267645
|
9.8 |
CRITICAL
Network
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, the use of an out-of-range pointer offset is potentially possible in LTE.
|
CWE-476
NULL Pointer Dereference
|
CVE-2016-10344
|
2024-11-21 11:43 |
2017-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267646
|
9.8 |
CRITICAL
Network
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, sSL handshake failure with ClientHello rejection results in memory leak.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-10343
|
2024-11-21 11:43 |
2017-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267647
|
6.1 |
MEDIUM
Network
|
liferay
|
liferay_portal
|
XSS exists in Liferay Portal before 7.0 CE GA4 via a crafted redirect field to modules/apps/foundation/frontend-js/frontend-js-spa-web/src/main/resources/META-INF/resources/init.jsp.
|
CWE-79
Cross-site Scripting
|
CVE-2016-10404
|
2024-11-21 11:43 |
2017-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267648
|
7.5 |
HIGH
Network
|
sendio
|
sendio
|
Sendio versions before 8.2.1 were affected by a Local File Inclusion vulnerability that allowed an unauthenticated, remote attacker to read potentially sensitive system files via a specially crafted …
|
CWE-538
File and Directory Information Exposure
|
CVE-2016-10399
|
2024-11-21 11:43 |
2017-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267649
|
7.8 |
HIGH
Local
|
avira
|
antivirus
|
Avira Antivirus engine versions before 8.3.36.60 allow remote code execution as NT AUTHORITY\SYSTEM via a section header with a very large relative virtual address in a PE file, causing an integer ov…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-10402
|
2024-11-21 11:43 |
2017-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267650
|
8.8 |
HIGH
Network
|
zyxel
|
pk5001z_firmware
|
ZyXEL PK5001Z devices have zyad5001 as the su password, which makes it easier for remote attackers to obtain root access if a non-root account password is known (or a non-root default account exists …
|
CWE-255
Credentials Management
|
CVE-2016-10401
|
2024-11-21 11:43 |
2017-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|