|
266481
|
7.2 |
HIGH
Network
|
paloaltonetworks
|
pan-os
|
The device management command line interface (CLI) in Palo Alto Networks PAN-OS before 5.0.18, 5.1.x before 5.1.11, 6.0.x before 6.0.13, 6.1.x before 6.1.10, and 7.0.x before 7.0.5H2 allows remote au…
|
CWE-20
Improper Input Validation
|
CVE-2016-3654
|
2024-11-21 11:50 |
2016-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266482
|
7.5 |
HIGH
Network
|
huawei
|
s5300_firmware s5700_firmware s7700_firmware s9300_firmware s9700_firmware
|
Huawei Quidway S9700, S5700, S5300, S9300, and S7700 switches with software before V200R003SPH012 allow remote attackers to cause a denial of service (switch restart) via crafted traffic.
|
CWE-20
Improper Input Validation
|
CVE-2016-3678
|
2024-11-21 11:50 |
2016-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266483
|
6.4 |
MEDIUM
Adjacent
|
huawei
|
e3276s_firmware
|
Huawei E3276s USB modems with software before E3276s-150TCPU-V200R002B436D09SP00C00 allow man-in-the-middle attackers to intercept, spoof, or modify network traffic via unspecified vectors related to…
|
CWE-254
7PK - Security Features
|
CVE-2016-3676
|
2024-11-21 11:50 |
2016-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266484
|
8.1 |
HIGH
Network
|
huawei
|
policy_center_firmware
|
SQL injection vulnerability in Huawei Policy Center with software before V100R003C10SPC020 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors related to syste…
|
CWE-89
SQL Injection
|
CVE-2016-3675
|
2024-11-21 11:50 |
2016-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266485
|
8.8 |
HIGH
Network
|
cacti
|
cacti
|
SQL injection vulnerability in graph_view.php in Cacti 0.8.8.g allows remote authenticated users to execute arbitrary SQL commands via the host_group_data parameter.
|
CWE-89
SQL Injection
|
CVE-2016-3659
|
2024-11-21 11:50 |
2016-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266486
|
8.8 |
HIGH
Network
|
google canonical opensuse
|
v8 ubuntu_linux opensuse chrome
|
Multiple unspecified vulnerabilities in Google V8 before 4.9.385.33, as used in Google Chrome before 49.0.2623.108, allow attackers to cause a denial of service or possibly have other impact via unkn…
|
NVD-CWE-noinfo
|
CVE-2016-3679
|
2024-11-21 11:50 |
2016-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266487
|
5.4 |
MEDIUM
Network
|
thoughtbot
|
administrate
|
Cross-site request forgery (CSRF) vulnerability in administrate 0.1.4 and earlier allows remote attackers to hijack the user's OAuth autorization code.
|
CWE-352
Origin Validation Error
|
CVE-2016-3098
|
2024-11-21 11:49 |
2022-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266488
|
5.5 |
MEDIUM
Local
|
uclouvain
|
openjpeg
|
The color_esycc_to_rgb function in bin/common/color.c in OpenJPEG before 2.1.1 allows attackers to cause a denial of service (memory corruption) via a crafted jpeg 2000 file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-3182
|
2024-11-21 11:49 |
2020-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266489
|
6.5 |
MEDIUM
Network
|
cloudera
|
cloudera_manager
|
Cloudera Manager 5.x before 5.7.1 places Sensitive Data in cleartext Readable Files.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2016-3192
|
2024-11-21 11:49 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266490
|
6.5 |
MEDIUM
Network
|
cloudera
|
cdh
|
Cloudera CDH before 5.6.1 allows authorization bypass via direct internal API calls.
|
CWE-863
Incorrect Authorization
|
CVE-2016-3131
|
2024-11-21 11:49 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|