|
265781
|
6.1 |
MEDIUM
Network
|
huawei
|
agile_controller-campus
|
Cross-site scripting (XSS) vulnerability in an unspecified portal authentication page in Huawei Agile Controller-Campus with software before V100R001C00SPC319 allows remote attackers to inject arbitr…
|
CWE-79
Cross-site Scripting
|
CVE-2016-2214
|
2024-11-21 11:48 |
2016-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265782
|
9.8 |
CRITICAL
Network
|
openelec
|
openelec
|
OpenELEC and RasPlex devices have a hardcoded password for the root account, which makes it easier for remote attackers to obtain access via an SSH session.
|
CWE-255
Credentials Management
|
CVE-2016-2230
|
2024-11-21 11:48 |
2016-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265783
|
5.3 |
MEDIUM
Network
|
siemens
|
simatic_s7-1500_cpu_firmware
|
Siemens SIMATIC S7-1500 CPU devices before 1.8.3 allow remote attackers to bypass a replay protection mechanism via packets on TCP port 102.
|
CWE-20
Improper Input Validation
|
CVE-2016-2201
|
2024-11-21 11:48 |
2016-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265784
|
7.5 |
HIGH
Network
|
siemens
|
simatic_s7-1500_cpu_firmware
|
Siemens SIMATIC S7-1500 CPU devices before 1.8.3 allow remote attackers to cause a denial of service (STOP mode transition) via crafted packets on TCP port 102.
|
CWE-20
Improper Input Validation
|
CVE-2016-2200
|
2024-11-21 11:48 |
2016-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265785
|
6.5 |
MEDIUM
Network
|
ffmpeg
|
ffmpeg
|
The jpeg2000_decode_tile function in libavcodec/jpeg2000dec.c in FFmpeg before 2.8.6 allows remote attackers to cause a denial of service (out-of-bounds array read access) via crafted JPEG 2000 data.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-2213
|
2024-11-21 11:48 |
2016-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265786
|
8.8 |
HIGH
Network
|
mcafee
|
vulnerability_manager
|
Multiple cross-site request forgery (CSRF) vulnerabilities in the Organizations and Remediation management page in Enterprise Manager in McAfee Vulnerability Manager (MVM) before 7.5.10 allow remote …
|
CWE-352
Origin Validation Error
|
CVE-2016-2199
|
2024-11-21 11:48 |
2016-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265787
|
- |
|
-
|
-
|
In the Linux kernel before 4.8, usb_parse_endpoint in drivers/usb/core/config.c does not validate the wMaxPacketSize field of an endpoint descriptor. NOTE: This vulnerability only affects products th…
|
-
|
CVE-2016-20022
|
2024-11-21 11:47 |
2024-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265788
|
9.8 |
CRITICAL
Network
|
gentoo
|
portage
|
In Gentoo Portage before 3.0.47, there is missing PGP validation of executed code: the standalone emerge-webrsync downloads a .gpgsig file but does not perform signature verification. Unless emerge-w…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2016-20021
|
2024-11-21 11:47 |
2024-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265789
|
7.5 |
HIGH
Network
|
knexjs
|
knex
|
Knex Knex.js through 2.3.0 has a limited SQL injection vulnerability that can be exploited to ignore the WHERE clause of a SQL query.
|
CWE-89
SQL Injection
|
CVE-2016-20018
|
2024-11-21 11:47 |
2022-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265790
|
9.8 |
CRITICAL
Network
|
dlink
|
dsl-2750b_firmware
|
D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wild in 2016 through 2022.
|
CWE-77
Command Injection
|
CVE-2016-20017
|
2024-11-21 11:47 |
2022-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|