|
265631
|
5.5 |
MEDIUM
Local
|
linux canonical opensuse
|
linux_kernel ubuntu_linux leap
|
The adjust_branches function in kernel/bpf/verifier.c in the Linux kernel before 4.5 does not consider the delta in the backward-jump case, which allows local users to obtain sensitive information fr…
|
NVD-CWE-noinfo
|
CVE-2016-2383
|
2024-11-21 11:48 |
2016-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265632
|
8.1 |
HIGH
Network
|
allroundautomations
|
pl\/sql_developer
|
Allround Automations PL/SQL Developer 11 before 11.0.6 relies on unverified HTTP data for updates, which allows man-in-the-middle attackers to execute arbitrary code by modifying fields in the client…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2016-2346
|
2024-11-21 11:48 |
2016-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265633
|
7.5 |
HIGH
Network
|
systech
|
syslink_sl-1000_modular_gateway_firmware
|
SysLINK SL-1000 Machine-to-Machine (M2M) Modular Gateway devices with firmware before 01A.8 use the same hardcoded encryption key across different customers' installations, which allows attackers to …
|
CWE-310
Cryptographic Issues
|
CVE-2016-2333
|
2024-11-21 11:48 |
2016-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265634
|
8.8 |
HIGH
Network
|
systech
|
syslink_sl-1000_modular_gateway_firmware
|
flu.cgi in the web interface on SysLINK SL-1000 Machine-to-Machine (M2M) Modular Gateway devices with firmware before 01A.8 allows remote authenticated users to execute arbitrary commands via the 506…
|
CWE-77
Command Injection
|
CVE-2016-2332
|
2024-11-21 11:48 |
2016-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265635
|
9.8 |
CRITICAL
Network
|
systech
|
syslink_sl-1000_modular_gateway_firmware
|
The web interface on SysLINK SL-1000 Machine-to-Machine (M2M) Modular Gateway devices with firmware before 01A.8 has a default password, which makes it easier for remote attackers to obtain access vi…
|
CWE-255
Credentials Management
|
CVE-2016-2331
|
2024-11-21 11:48 |
2016-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265636
|
8.2 |
HIGH
Local
|
symantec
|
messaging_gateway
|
The management console on Symantec Messaging Gateway (SMG) Appliance devices before 10.6.1 allows local users to obtain root-shell access via crafted terminal-window input.
|
CWE-74
Injection
|
CVE-2016-2204
|
2024-11-21 11:48 |
2016-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265637
|
7.8 |
HIGH
Local
|
symantec
|
messaging_gateway
|
The management console on Symantec Messaging Gateway (SMG) Appliance devices before 10.6.1 allows local users to discover an encrypted AD password by leveraging certain read privileges.
|
CWE-255
Credentials Management
|
CVE-2016-2203
|
2024-11-21 11:48 |
2016-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265638
|
8.8 |
HIGH
Adjacent
|
lemurmonitors
|
bluedriver
|
The Bluetooth functionality in Lemur Vehicle Monitors BlueDriver before 2016-04-07 supports unrestricted pairing without a PIN, which allows remote attackers to send arbitrary CAN commands by leverag…
|
CWE-284
Improper Access Control
|
CVE-2016-2354
|
2024-11-21 11:48 |
2016-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265639
|
7.5 |
HIGH
Network
|
ecava
|
integraxor
|
The HMI web server in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to obtain sensitive cleartext information by sniffing the network.
|
CWE-310
Cryptographic Issues
|
CVE-2016-2306
|
2024-11-21 11:48 |
2016-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265640
|
6.1 |
MEDIUM
Network
|
ecava
|
integraxor
|
Cross-site scripting (XSS) vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
|
CWE-79
Cross-site Scripting
|
CVE-2016-2305
|
2024-11-21 11:48 |
2016-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|