|
265791
|
9.8 |
CRITICAL
Network
|
mvpower
|
tv-7104he_firmware tv7108he_firmware
|
MVPower CCTV DVR models, including TV-7104HE 1.8.4 115215B9 and TV7108HE, contain a web shell that is accessible via a /shell URI. A remote unauthenticated attacker can execute arbitrary operating sy…
|
NVD-CWE-noinfo
|
CVE-2016-20016
|
2024-11-21 11:47 |
2022-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265792
|
7.5 |
HIGH
Network
|
smokeping
|
smokeping
|
In the ebuild package through smokeping-2.7.3-r1 for SmokePing on Gentoo, the initscript allows the smokeping user to gain ownership of any file, allowing for the smokeping user to gain root privileg…
|
NVD-CWE-noinfo
|
CVE-2016-20015
|
2024-11-21 11:47 |
2022-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265793
|
6.4 |
MEDIUM
Network
|
kippo-graph_project
|
kippo-graph
|
In kippo-graph before version 1.5.1, there is a cross-site scripting vulnerability in $file_link in class/KippoInput.class.php.
|
CWE-79
Cross-site Scripting
|
CVE-2016-2139
|
2024-11-21 11:47 |
2022-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265794
|
6.4 |
MEDIUM
Network
|
kippo-graph_project
|
kippo-graph
|
In kippo-graph before version 1.5.1, there is a cross-site scripting vulnerability in xss_clean() in class/KippoInput.class.php.
|
CWE-79
Cross-site Scripting
|
CVE-2016-2138
|
2024-11-21 11:47 |
2022-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265795
|
9.8 |
CRITICAL
Network
|
pam_tacplus_project
|
pam_tacplus
|
In pam_tacplus.c in pam_tacplus before 1.4.1, pam_sm_acct_mgmt does not zero out the arep data structure.
|
NVD-CWE-Other
|
CVE-2016-20014
|
2024-11-21 11:47 |
2022-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265796
|
7.5 |
HIGH
Network
|
sha256crypt_project sha512crypt_project
|
sha256crypt sha512crypt
|
sha256crypt and sha512crypt through 0.6 allow attackers to cause a denial of service (CPU consumption) because the algorithm's runtime is proportional to the square of the length of the password.
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2016-20013
|
2024-11-21 11:47 |
2022-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265797
|
5.9 |
MEDIUM
Network
|
samba debian fedoraproject redhat canonical
|
samba debian_linux fedora enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_for_scientific_computing enterprise_linux enterprise_linux_server enterprise_l…
|
A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plaintext password sent over the wire even if Kerberos authentication was required.
|
CWE-287
Improper Authentication
|
CVE-2016-2124
|
2024-11-21 11:47 |
2022-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265798
|
5.3 |
MEDIUM
Network
|
openbsd netapp
|
openssh ontap_select_deploy_administration_utility clustered_data_ontap solidfire hci_management_node
|
OpenSSH through 8.7 allows remote attackers, who have a suspicion that a certain combination of username and public key is known to an SSH server, to test whether this suspicion is correct. This occu…
|
NVD-CWE-Other
|
CVE-2016-20012
|
2024-11-21 11:47 |
2021-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265799
|
7.5 |
HIGH
Network
|
gnome
|
libgrss
|
libgrss through 0.7.0 fails to perform TLS certificate verification when downloading feeds, allowing remote attackers to manipulate the contents of feeds without detection. This occurs because of the…
|
CWE-295
Improper Certificate Validation
|
CVE-2016-20011
|
2024-11-21 11:47 |
2021-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265800
|
10.0 |
CRITICAL
Network
|
ewww
|
image_optimizer
|
EWWW Image Optimizer before 2.8.5 allows remote command execution because it relies on a protection mechanism involving boolval, which is unavailable before PHP 5.5.
|
NVD-CWE-noinfo
|
CVE-2016-20010
|
2024-11-21 11:47 |
2021-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|