|
267521
|
7.5 |
HIGH
Network
|
postgresql canonical debian
|
postgresql ubuntu_linux debian_linux
|
PostgreSQL before 9.1.20, 9.2.x before 9.2.15, 9.3.x before 9.3.11, 9.4.x before 9.4.6, and 9.5.x before 9.5.1 allows remote attackers to cause a denial of service (infinite loop or buffer overflow a…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-0773
|
2024-11-21 11:42 |
2016-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267522
|
8.8 |
HIGH
Network
|
postgresql canonical debian
|
postgresql ubuntu_linux debian_linux
|
PostgreSQL before 9.1.20, 9.2.x before 9.2.15, 9.3.x before 9.3.11, 9.4.x before 9.4.6, and 9.5.x before 9.5.1 does not properly restrict access to unspecified custom configuration settings (GUCS) fo…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-0766
|
2024-11-21 11:42 |
2016-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267523
|
5.3 |
MEDIUM
Network
|
rubyonrails debian fedoraproject opensuse
|
rails debian_linux fedora leap
|
Active Model in Ruby on Rails 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 supports the use of instance-level writers for class accessors, which allows remote attackers t…
|
NVD-CWE-noinfo
|
CVE-2016-0753
|
2024-11-21 11:42 |
2016-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267524
|
7.5 |
HIGH
Network
|
rubyonrails
|
ruby_on_rails rails
|
actionpack/lib/action_dispatch/http/mime_type.rb in Action Pack in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not properly…
|
CWE-399
Resource Management Errors
|
CVE-2016-0751
|
2024-11-21 11:42 |
2016-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267525
|
5.3 |
MEDIUM
Network
|
f5 canonical debian opensuse apple
|
nginx ubuntu_linux debian_linux leap xcode
|
The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not properly limit CNAME resolution, which allows remote attackers to cause a denial of service (worker process resource consumption) v…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2016-0747
|
2024-11-21 11:42 |
2016-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267526
|
9.8 |
CRITICAL
Network
|
f5 canonical debian opensuse apple
|
nginx ubuntu_linux debian_linux leap xcode
|
Use-after-free vulnerability in the resolver in nginx 0.6.18 through 1.8.0 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (worker process crash) or possibly have unspeci…
|
CWE-416
Use After Free
|
CVE-2016-0746
|
2024-11-21 11:42 |
2016-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267527
|
7.5 |
HIGH
Network
|
f5 canonical debian opensuse apple redhat
|
nginx ubuntu_linux debian_linux leap xcode software_collections
|
The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (invalid pointer dereference and worker process crash) via a crafted UDP DNS response.
|
CWE-476
NULL Pointer Dereference
|
CVE-2016-0742
|
2024-11-21 11:42 |
2016-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267528
|
3.7 |
LOW
Network
|
openssl
|
openssl
|
The DH_check_pub_key function in crypto/dh/dh_check.c in OpenSSL 1.0.2 before 1.0.2f does not ensure that prime numbers are appropriate for Diffie-Hellman (DH) key exchange, which makes it easier for…
|
CWE-200
Information Exposure
|
CVE-2016-0701
|
2024-11-21 11:42 |
2016-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267529
|
6.1 |
MEDIUM
Network
|
tollgrade
|
smartgrid_lighthouse_sensor_management_system
|
Cross-site scripting (XSS) vulnerability in Tollgrade SmartGrid LightHouse Sensor Management System (SMS) Software EMS before 5.1, and 4.1.0 Build 16, allows remote attackers to inject arbitrary web …
|
CWE-79
Cross-site Scripting
|
CVE-2016-0866
|
2024-11-21 11:42 |
2016-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267530
|
8.8 |
HIGH
Network
|
tollgrade
|
smartgrid_lighthouse_sensor_management_system
|
Tollgrade SmartGrid LightHouse Sensor Management System (SMS) Software EMS before 5.1, and 4.1.0 Build 16, allows remote authenticated users to change arbitrary passwords via unspecified vectors.
|
CWE-255
Credentials Management
|
CVE-2016-0865
|
2024-11-21 11:42 |
2016-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|