|
266651
|
8.4 |
HIGH
Local
|
ecryptfs canonical opensuse debian fedoraproject
|
ecryptfs-utils ubuntu_linux leap opensuse debian_linux fedora
|
mount.ecryptfs_private.c in eCryptfs-utils does not validate mount destination filesystem types, which allows local users to gain privileges by mounting over a nonstandard filesystem, as demonstrated…
|
CWE-269
Improper Privilege Management
|
CVE-2016-1572
|
2024-11-21 11:46 |
2016-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266652
|
6.3 |
MEDIUM
Network
|
citrix xen
|
xenserver xen
|
The paging_invlpg function in include/asm-x86/paging.h in Xen 3.3.x through 4.6.x, when using shadow mode paging or nested virtualization is enabled, allows local HVM guest users to cause a denial of…
|
CWE-17
Code
|
CVE-2016-1571
|
2024-11-21 11:46 |
2016-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266653
|
8.5 |
HIGH
Network
|
xen
|
xen
|
The PV superpage functionality in arch/x86/mm.c in Xen 3.4.0, 3.4.1, and 4.1.x through 4.6.x allows local PV guests to obtain sensitive information, cause a denial of service, gain privileges, or hav…
|
CWE-20
Improper Input Validation
|
CVE-2016-1570
|
2024-11-21 11:46 |
2016-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266654
|
7.5 |
HIGH
Network
|
cisco
|
web_security_appliance
|
The proxy engine on Cisco Web Security Appliance (WSA) devices with software 8.5.3-055, 9.1.0-000, and 9.5.0-235 allows remote attackers to bypass intended proxy restrictions via a malformed HTTP met…
|
CWE-254
7PK - Security Features
|
CVE-2016-1296
|
2024-11-21 11:46 |
2016-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266655
|
5.3 |
MEDIUM
Network
|
cisco
|
adaptive_security_appliance_software
|
Cisco Adaptive Security Appliance (ASA) Software 8.4 allows remote attackers to obtain sensitive information via an AnyConnect authentication attempt, aka Bug ID CSCuo65775.
|
CWE-200
Information Exposure
|
CVE-2016-1295
|
2024-11-21 11:46 |
2016-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266656
|
6.1 |
MEDIUM
Network
|
cisco
|
firesight_system_software
|
Cross-site scripting (XSS) vulnerability in the Management Center in Cisco FireSIGHT System Software 6.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted cookie, aka Bug…
|
CWE-79
Cross-site Scripting
|
CVE-2016-1294
|
2024-11-21 11:46 |
2016-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266657
|
6.1 |
MEDIUM
Network
|
cisco
|
firesight_system_software
|
Multiple cross-site scripting (XSS) vulnerabilities in the Management Center in Cisco FireSIGHT System Software 6.0.0 and 6.0.1 allow remote attackers to inject arbitrary web script or HTML via unspe…
|
CWE-79
Cross-site Scripting
|
CVE-2016-1293
|
2024-11-21 11:46 |
2016-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266658
|
5.9 |
MEDIUM
Network
|
juniper
|
junos
|
Juniper Junos OS before 12.1X46-D45, 12.1X47 before 12.1X47-D30, 12.1X48 before 12.3X48-D20, and 15.1X49 before 15.1X49-D30 on SRX series devices, when the Real Time Streaming Protocol Application La…
|
CWE-20
Improper Input Validation
|
CVE-2016-1262
|
2024-11-21 11:46 |
2016-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266659
|
5.3 |
MEDIUM
Network
|
juniper
|
junos
|
Juniper Junos OS before 13.2X51-D36, 14.1X53 before 14.1X53-D25, and 15.2 before 15.2R1 on EX4300 series switches allow remote attackers to cause a denial of service (network loop and bandwidth consu…
|
CWE-399
Resource Management Errors
|
CVE-2016-1260
|
2024-11-21 11:46 |
2016-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266660
|
5.3 |
MEDIUM
Network
|
juniper
|
junos
|
Embedthis Appweb, as used in J-Web in Juniper Junos OS before 12.1X44-D60, 12.1X46 before 12.1X46-D45, 12.1X47 before 12.1X47-D30, 12.3 before 12.3R10, 12.3X48 before 12.3X48-D20, 13.2X51 before 13.2…
|
CWE-20
Improper Input Validation
|
CVE-2016-1258
|
2024-11-21 11:46 |
2016-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|