|
265781
|
8.6 |
HIGH
Network
|
cisco
|
firesight_system_software
|
Cisco Firepower System Software 6.0.0 through 6.1.0 has a hardcoded account, which allows remote attackers to obtain CLI access by leveraging knowledge of the password, aka Bug ID CSCuz56238.
|
CWE-255 CWE-264
Credentials Management Permissions, Privileges, and Access Controls
|
CVE-2016-1394
|
2024-11-21 11:46 |
2016-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265782
|
5.3 |
MEDIUM
Network
|
cisco
|
web_security_appliance
|
The proxy process on Cisco Web Security Appliance (WSA) devices through 9.1.0-070 allows remote attackers to cause a denial of service (CPU consumption) by establishing an FTP session and then improp…
|
CWE-399
Resource Management Errors
|
CVE-2016-1440
|
2024-11-21 11:46 |
2016-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265783
|
9.8 |
CRITICAL
Network
|
cisco
|
prime_collaboration_provisioning
|
Cisco Prime Collaboration Provisioning 10.6 SP2 (aka 10.6.0.10602) mishandles LDAP authentication, which allows remote attackers to obtain administrator privileges via a crafted login attempt, aka Bu…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-1416
|
2024-11-21 11:46 |
2016-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265784
|
8.8 |
HIGH
Network
|
cisco
|
prime_infrastructure evolved_programmable_network_manager
|
Cisco Prime Infrastructure 1.2 through 3.1 and Evolved Programmable Network Manager (EPNM) 1.2 and 2.0 allow remote authenticated users to execute arbitrary commands or upload files via a crafted HTT…
|
CWE-20
Improper Input Validation
|
CVE-2016-1408
|
2024-11-21 11:46 |
2016-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265785
|
9.8 |
CRITICAL
Network
|
cisco
|
prime_infrastructure evolved_programmable_network_manager
|
The API in Cisco Prime Infrastructure 1.2 through 3.0 and Evolved Programmable Network Manager (EPNM) 1.2 allows remote attackers to execute arbitrary code or obtain sensitive management information …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-1289
|
2024-11-21 11:46 |
2016-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265786
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
nfsd in the Linux kernel through 4.6.3 allows local users to bypass intended file-permission restrictions by setting a POSIX ACL, related to nfs2acl.c, nfs3acl.c, and nfs4acl.c.
|
CWE-284
Improper Access Control
|
CVE-2016-1237
|
2024-11-21 11:46 |
2016-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265787
|
7.8 |
HIGH
Local
|
linux novell canonical debian
|
linux_kernel suse_linux_enterprise_server suse_linux_enterprise_live_patching suse_linux_enterprise_desktop suse_linux_enterprise_module_for_public_cloud suse_linux_enterprise_workstat…
|
The ecryptfs_privileged_open function in fs/ecryptfs/kthread.c in the Linux kernel before 4.6.3 allows local users to gain privileges or cause a denial of service (stack memory consumption) via vecto…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-1583
|
2024-11-21 11:46 |
2016-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265788
|
6.1 |
MEDIUM
Network
|
cisco
|
unified_contact_center_enterprise
|
Cross-site scripting (XSS) vulnerability in the management interface in Cisco Unified Contact Center Enterprise through 10.5(2) allows remote attackers to inject arbitrary web script or HTML via a cr…
|
CWE-79
Cross-site Scripting
|
CVE-2016-1439
|
2024-11-21 11:46 |
2016-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265789
|
7.5 |
HIGH
Network
|
cisco
|
asyncos
|
Cisco AsyncOS 9.7.0-125 on Email Security Appliance (ESA) devices allows remote attackers to bypass intended spam filtering via crafted executable content in a ZIP archive, aka Bug ID CSCuy39210.
|
CWE-20 CWE-254
Improper Input Validation 7PK - Security Features
|
CVE-2016-1438
|
2024-11-21 11:46 |
2016-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265790
|
6.5 |
MEDIUM
Network
|
cisco
|
prime_collaboration_deployment
|
SQL injection vulnerability in the SQL database in Cisco Prime Collaboration Deployment before 11.5.1 allows remote authenticated users to execute arbitrary SQL commands via a crafted URL, aka Bug ID…
|
CWE-89
SQL Injection
|
CVE-2016-1437
|
2024-11-21 11:46 |
2016-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|