|
266021
|
7.5 |
HIGH
Network
|
huawei
|
s5300_firmware s5700_firmware s7700_firmware s9300_firmware s9700_firmware
|
Huawei Quidway S9700, S5700, S5300, S9300, and S7700 switches with software before V200R003SPH012 allow remote attackers to cause a denial of service (switch restart) via crafted traffic.
|
CWE-20
Improper Input Validation
|
CVE-2016-3678
|
2024-11-21 11:50 |
2016-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266022
|
6.4 |
MEDIUM
Adjacent
|
huawei
|
e3276s_firmware
|
Huawei E3276s USB modems with software before E3276s-150TCPU-V200R002B436D09SP00C00 allow man-in-the-middle attackers to intercept, spoof, or modify network traffic via unspecified vectors related to…
|
CWE-254
7PK - Security Features
|
CVE-2016-3676
|
2024-11-21 11:50 |
2016-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266023
|
8.1 |
HIGH
Network
|
huawei
|
policy_center_firmware
|
SQL injection vulnerability in Huawei Policy Center with software before V100R003C10SPC020 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors related to syste…
|
CWE-89
SQL Injection
|
CVE-2016-3675
|
2024-11-21 11:50 |
2016-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266024
|
8.8 |
HIGH
Network
|
cacti
|
cacti
|
SQL injection vulnerability in graph_view.php in Cacti 0.8.8.g allows remote authenticated users to execute arbitrary SQL commands via the host_group_data parameter.
|
CWE-89
SQL Injection
|
CVE-2016-3659
|
2024-11-21 11:50 |
2016-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266025
|
8.8 |
HIGH
Network
|
google canonical opensuse
|
v8 ubuntu_linux opensuse chrome
|
Multiple unspecified vulnerabilities in Google V8 before 4.9.385.33, as used in Google Chrome before 49.0.2623.108, allow attackers to cause a denial of service or possibly have other impact via unkn…
|
NVD-CWE-noinfo
|
CVE-2016-3679
|
2024-11-21 11:50 |
2016-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266026
|
5.4 |
MEDIUM
Network
|
thoughtbot
|
administrate
|
Cross-site request forgery (CSRF) vulnerability in administrate 0.1.4 and earlier allows remote attackers to hijack the user's OAuth autorization code.
|
CWE-352
Origin Validation Error
|
CVE-2016-3098
|
2024-11-21 11:49 |
2022-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266027
|
5.5 |
MEDIUM
Local
|
uclouvain
|
openjpeg
|
The color_esycc_to_rgb function in bin/common/color.c in OpenJPEG before 2.1.1 allows attackers to cause a denial of service (memory corruption) via a crafted jpeg 2000 file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-3182
|
2024-11-21 11:49 |
2020-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266028
|
6.5 |
MEDIUM
Network
|
cloudera
|
cloudera_manager
|
Cloudera Manager 5.x before 5.7.1 places Sensitive Data in cleartext Readable Files.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2016-3192
|
2024-11-21 11:49 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266029
|
6.5 |
MEDIUM
Network
|
cloudera
|
cdh
|
Cloudera CDH before 5.6.1 allows authorization bypass via direct internal API calls.
|
CWE-863
Incorrect Authorization
|
CVE-2016-3131
|
2024-11-21 11:49 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266030
|
5.9 |
MEDIUM
Network
|
ibm
|
rational_clearquest
|
IBM Rational ClearQuest 8.0 through 8.0.1.9 and 9.0 through 9.0.1.3 (CQ OSLC linkages, EmailRelay) fails to check the SSL certificate against the requested hostname. It is subject to a man-in-the-mid…
|
CWE-295
Improper Certificate Validation
|
CVE-2016-2922
|
2024-11-21 11:49 |
2018-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|