|
266861
|
7.2 |
HIGH
Network
|
dotcms
|
dotcms
|
SQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS before 3.7.2 and 4.x before 4.1.1 allows remote authenticated administrators to execute arbitrary SQL commands via …
|
CWE-89
SQL Injection
|
CVE-2016-10008
|
2024-11-21 11:43 |
2018-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266862
|
7.2 |
HIGH
Network
|
dotcms
|
dotcms
|
SQL injection vulnerability in the "Marketing > Forms" screen in dotCMS before 3.7.2 and 4.x before 4.1.1 allows remote authenticated administrators to execute arbitrary SQL commands via the _EXT_FOR…
|
CWE-89
SQL Injection
|
CVE-2016-10007
|
2024-11-21 11:43 |
2018-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266863
|
6.1 |
MEDIUM
Network
|
broadcom
|
advanced_secure_gateway symantec_proxysg
|
The Symantec Advanced Secure Gateway (ASG) 6.6, ASG 6.7 (prior to 6.7.2.1), ProxySG 6.5 (prior to 6.5.10.6), ProxySG 6.6, and ProxySG 6.7 (prior to 6.7.2.1) management console is susceptible to a ref…
|
CWE-79
Cross-site Scripting
|
CVE-2016-10257
|
2024-11-21 11:43 |
2018-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266864
|
6.1 |
MEDIUM
Network
|
broadcom
|
symantec_proxysg
|
The Symantec ProxySG 6.5 (prior to 6.5.10.6), 6.6, and 6.7 (prior to 6.7.2.1) management console is susceptible to a reflected XSS vulnerability. A remote attacker can use a crafted management consol…
|
CWE-79
Cross-site Scripting
|
CVE-2016-10256
|
2024-11-21 11:43 |
2018-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266865
|
9.8 |
CRITICAL
Network
|
d-link
|
dir-600l_firmware
|
Session fixation vulnerability in D-Link DIR-600L routers (rev. Ax) with firmware before FW1.17.B01 allows remote attackers to hijack web sessions via unspecified vectors.
|
CWE-384
Session Fixation
|
CVE-2016-10405
|
2024-11-21 11:43 |
2017-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266866
|
9.8 |
CRITICAL
Network
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, a driver can potentially leak kernel memory.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-10392
|
2024-11-21 11:43 |
2017-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266867
|
9.8 |
CRITICAL
Network
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, the length in an HCI command is not properly checked for validity.
|
CWE-20
Improper Input Validation
|
CVE-2016-10391
|
2024-11-21 11:43 |
2017-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266868
|
9.8 |
CRITICAL
Network
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, when downloading a file, an excessive amount of memory may be consumed.
|
CWE-399
Resource Management Errors
|
CVE-2016-10390
|
2024-11-21 11:43 |
2017-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266869
|
7.8 |
HIGH
Local
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, there is no size check for the images being flashed onto the NAND memory in their respective partitions, so there is a …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-10389
|
2024-11-21 11:43 |
2017-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266870
|
9.8 |
CRITICAL
Network
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, a configuration vulnerability exists when loading a 3rd-party QTEE application.
|
CWE-16
Configuration
|
CVE-2016-10388
|
2024-11-21 11:43 |
2017-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|