|
265741
|
9.8 |
CRITICAL
Network
|
cisco
|
ucs_invicta_c3124sa_appliance
|
Cisco UCS Invicta C3124SA Appliance 4.3.1 through 5.0.1, UCS Invicta Scaling System and Appliance, and Whiptail Racerunner improperly store a default SSH private key, which allows remote attackers to…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-1313
|
2024-11-21 11:46 |
2016-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265742
|
9.8 |
CRITICAL
Network
|
cisco sun
|
prime_infrastructure opensolaris evolved_programmable_network_manager
|
Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allow remote attackers to execute arbitrary code via crafted deserialized data in an HTTP POS…
|
CWE-20
Improper Input Validation
|
CVE-2016-1291
|
2024-11-21 11:46 |
2016-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265743
|
8.1 |
HIGH
Network
|
cisco sun
|
prime_infrastructure opensolaris evolved_programmable_network_manager
|
The web API in Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allows remote authenticated users to bypass intended RBAC restrictions and gai…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-1290
|
2024-11-21 11:46 |
2016-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265744
|
7.5 |
HIGH
Network
|
cisco
|
firesight_system_software asa_with_firepower_services
|
Cisco FireSIGHT System Software 5.4.0 through 6.0.1 and ASA with FirePOWER Services 5.4.0 through 6.0.0.1 allow remote attackers to bypass malware protection via crafted fields in HTTP headers, aka B…
|
CWE-20
Improper Input Validation
|
CVE-2016-1345
|
2024-11-21 11:46 |
2016-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265745
|
8.8 |
HIGH
Network
|
opensuse debian google
|
opensuse debian_linux chrome
|
The PageCaptureSaveAsMHTMLFunction::ReturnFailure function in browser/extensions/api/page_capture/page_capture_api.cc in Google Chrome before 49.0.2623.108 allows attackers to cause a denial of servi…
|
NVD-CWE-noinfo
|
CVE-2016-1650
|
2024-11-21 11:46 |
2016-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265746
|
8.8 |
HIGH
Network
|
debian canonical opensuse google
|
debian_linux ubuntu_linux opensuse chrome
|
The Program::getUniformInternal function in Program.cpp in libANGLE, as used in Google Chrome before 49.0.2623.108, does not properly handle a certain data-type mismatch, which allows remote attacker…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-1649
|
2024-11-21 11:46 |
2016-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265747
|
8.8 |
HIGH
Network
|
google opensuse debian
|
chrome opensuse debian_linux
|
Use-after-free vulnerability in the GetLoadTimes function in renderer/loadtimes_extension_bindings.cc in the Extensions implementation in Google Chrome before 49.0.2623.108 allows remote attackers to…
|
NVD-CWE-Other
|
CVE-2016-1648
|
2024-11-21 11:46 |
2016-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265748
|
8.8 |
HIGH
Network
|
google canonical debian opensuse
|
chrome ubuntu_linux debian_linux opensuse
|
Use-after-free vulnerability in the RenderWidgetHostImpl::Destroy function in content/browser/renderer_host/render_widget_host_impl.cc in the Navigation implementation in Google Chrome before 49.0.26…
|
NVD-CWE-Other
|
CVE-2016-1647
|
2024-11-21 11:46 |
2016-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265749
|
6.1 |
MEDIUM
Network
|
sun
|
opensolaris
|
Cross-site scripting (XSS) vulnerability in Cisco Unified Communications Domain Manager (CDM) 8.1(1) allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, aka Bu…
|
CWE-79
Cross-site Scripting
|
CVE-2016-1314
|
2024-11-21 11:46 |
2016-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265750
|
7.5 |
HIGH
Network
|
cisco
|
nx-os ios
|
The Locator/ID Separation Protocol (LISP) implementation in Cisco IOS 15.1 and 15.2 and NX-OS 4.1 through 6.2 allows remote attackers to cause a denial of service (device reload) via a crafted header…
|
CWE-20 CWE-399
Improper Input Validation Resource Management Errors
|
CVE-2016-1351
|
2024-11-21 11:46 |
2016-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|