|
265841
|
7.5 |
HIGH
Network
|
squid-cache
|
squid
|
Squid 3.x before 3.5.16 and 4.x before 4.0.8 improperly perform bounds checking, which allows remote attackers to cause a denial of service via a crafted HTTP response, related to Vary headers.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-3948
|
2024-11-21 11:51 |
2016-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265842
|
8.2 |
HIGH
Network
|
squid-cache canonical
|
squid ubuntu_linux
|
Heap-based buffer overflow in the Icmp6::Recv function in icmp/Icmp6.cc in the pinger utility in Squid before 3.5.16 and 4.x before 4.0.8 allows remote servers to cause a denial of service (performan…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-3947
|
2024-11-21 11:51 |
2016-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265843
|
6.1 |
MEDIUM
Network
|
mcafee
|
email_gateway
|
Cross-site scripting (XSS) vulnerability in McAfee Email Gateway (MEG) 7.6.x before 7.6.404, when File Filtering is enabled with the action set to ESERVICES:REPLACE, allows remote attackers to inject…
|
CWE-79
Cross-site Scripting
|
CVE-2016-3969
|
2024-11-21 11:51 |
2016-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265844
|
6.1 |
MEDIUM
Network
|
sophos
|
cyberoam_cr100ing_utm_firmware cyberoam_cr35ing_utm_firmware
|
Multiple cross-site scripting (XSS) vulnerabilities in Sophos Cyberoam CR100iNG UTM appliance with firmware 10.6.3 MR-1 build 503, CR35iNG UTM appliance with firmware 10.6.2 MR-1 build 383, and CR35i…
|
CWE-79
Cross-site Scripting
|
CVE-2016-3968
|
2024-11-21 11:51 |
2016-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265845
|
6.1 |
MEDIUM
Network
|
xmlsoft
|
libxml2
|
Possible cross-site scripting vulnerability in libxml after commit 960f0e2.
|
CWE-79
Cross-site Scripting
|
CVE-2016-3709
|
2024-11-21 11:50 |
2022-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265846
|
8.1 |
HIGH
Network
|
piwigo
|
piwigo
|
Piwigo is image gallery software written in PHP. When a criteria is not met on a host, piwigo defaults to usingmt_rand in order to generate password reset tokens. mt_rand output can be predicted afte…
|
CWE-335
Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG)
|
CVE-2016-3735
|
2024-11-21 11:50 |
2022-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265847
|
5.5 |
MEDIUM
Local
|
linux redhat
|
linux_kernel enterprise_linux
|
The einj_error_inject function in drivers/acpi/apei/einj.c in the Linux kernel allows local users to simulate hardware errors and consequently cause a denial of service by leveraging failure to disab…
|
CWE-74
Injection
|
CVE-2016-3695
|
2024-11-21 11:50 |
2017-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265848
|
7.5 |
HIGH
Network
|
fedoraproject pulpproject
|
fedora pulp
|
Pulp before 2.8.5 uses bash's $RANDOM in an unsafe way to generate passwords.
|
CWE-255
Credentials Management
|
CVE-2016-3704
|
2024-11-21 11:50 |
2017-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265849
|
5.5 |
MEDIUM
Local
|
fedoraproject pulpproject
|
fedora pulp
|
The pulp-qpid-ssl-cfg script in Pulp before 2.8.5 allows local users to obtain the CA key.
|
CWE-200
Information Exposure
|
CVE-2016-3696
|
2024-11-21 11:50 |
2017-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265850
|
9.8 |
CRITICAL
Network
|
redhat
|
jboss_enterprise_application_platform
|
The PooledInvokerServlet in JBoss EAP 4.x and 5.x allows remote attackers to execute arbitrary code via a crafted serialized payload.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2016-3690
|
2024-11-21 11:50 |
2017-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|