|
267171
|
7.0 |
HIGH
Local
|
exim
|
exim
|
Exim before 4.86.2, when installed setuid root, allows local users to gain privileges via the perl_startup argument.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-1531
|
2024-11-21 11:46 |
2016-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267172
|
8.1 |
HIGH
Local
|
redhat oracle qemu
|
openstack linux qemu
|
The (1) fw_cfg_write and (2) fw_cfg_read functions in hw/nvram/fw_cfg.c in QEMU before 2.4, when built with the Firmware Configuration device emulation support, allow guest OS users with the CAP_SYS_…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-1714
|
2024-11-21 11:46 |
2016-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267173
|
6.8 |
MEDIUM
Network
|
netapp
|
clustered_data_ontap
|
NetApp Clustered Data ONTAP 8.3.1 does not properly verify X.509 certificates from TLS servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafte…
|
CWE-200 CWE-20
Information Exposure Improper Input Validation
|
CVE-2016-1563
|
2024-11-21 11:46 |
2016-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267174
|
5.9 |
MEDIUM
Network
|
dell netgear samsung zyxel zzinc
|
emc_powerscale_onefs jr6150_firmware x14j_firmware gs1900-10hp_firmware keymouse_firmware
|
The kernel in Cisco TelePresence Server 3.0 through 4.2(4.18) on Mobility Services Engine (MSE) 8710 devices allows remote attackers to cause a denial of service (panic and reboot) via a crafted sequ…
|
CWE-399
Resource Management Errors
|
CVE-2016-1346
|
2024-11-21 11:46 |
2016-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267175
|
9.8 |
CRITICAL
Network
|
cisco
|
ucs_invicta_c3124sa_appliance
|
Cisco UCS Invicta C3124SA Appliance 4.3.1 through 5.0.1, UCS Invicta Scaling System and Appliance, and Whiptail Racerunner improperly store a default SSH private key, which allows remote attackers to…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-1313
|
2024-11-21 11:46 |
2016-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267176
|
9.8 |
CRITICAL
Network
|
cisco sun
|
prime_infrastructure opensolaris evolved_programmable_network_manager
|
Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allow remote attackers to execute arbitrary code via crafted deserialized data in an HTTP POS…
|
CWE-20
Improper Input Validation
|
CVE-2016-1291
|
2024-11-21 11:46 |
2016-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267177
|
8.1 |
HIGH
Network
|
cisco sun
|
prime_infrastructure opensolaris evolved_programmable_network_manager
|
The web API in Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allows remote authenticated users to bypass intended RBAC restrictions and gai…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-1290
|
2024-11-21 11:46 |
2016-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267178
|
7.5 |
HIGH
Network
|
cisco
|
firesight_system_software asa_with_firepower_services
|
Cisco FireSIGHT System Software 5.4.0 through 6.0.1 and ASA with FirePOWER Services 5.4.0 through 6.0.0.1 allow remote attackers to bypass malware protection via crafted fields in HTTP headers, aka B…
|
CWE-20
Improper Input Validation
|
CVE-2016-1345
|
2024-11-21 11:46 |
2016-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267179
|
8.8 |
HIGH
Network
|
opensuse debian google
|
opensuse debian_linux chrome
|
The PageCaptureSaveAsMHTMLFunction::ReturnFailure function in browser/extensions/api/page_capture/page_capture_api.cc in Google Chrome before 49.0.2623.108 allows attackers to cause a denial of servi…
|
NVD-CWE-noinfo
|
CVE-2016-1650
|
2024-11-21 11:46 |
2016-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267180
|
8.8 |
HIGH
Network
|
debian canonical opensuse google
|
debian_linux ubuntu_linux opensuse chrome
|
The Program::getUniformInternal function in Program.cpp in libANGLE, as used in Google Chrome before 49.0.2623.108, does not properly handle a certain data-type mismatch, which allows remote attacker…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-1649
|
2024-11-21 11:46 |
2016-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|