|
267411
|
9.8 |
CRITICAL
Network
|
fedoraproject vmware
|
fedora spring_advanced_message_queuing_protocol
|
org.springframework.core.serializer.DefaultDeserializer in Spring AMQP before 1.5.5 allows remote attackers to execute arbitrary code.
|
CWE-20
Improper Input Validation
|
CVE-2016-2173
|
2024-11-21 11:47 |
2017-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267412
|
5.5 |
MEDIUM
Local
|
samsung
|
galaxy_s6_firmware galaxy_note_3_firmware
|
The getURL function in drivers/secfilter/urlparser.c in secfilter in the Samsung kernel for Android on SM-N9005 build N9005XXUGBOB6 (Note 3) and SM-G920F build G920FXXU2COH2 (Galaxy S6) devices allow…
|
CWE-476
NULL Pointer Dereference
|
CVE-2016-2036
|
2024-11-21 11:47 |
2017-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267413
|
6.1 |
MEDIUM
Network
|
redhat
|
satellite
|
Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Satellite 5 allow remote attackers to inject arbitrary web script or HTML via (1) the label parameter to admin/BunchDetail.do; (2) the p…
|
CWE-79
Cross-site Scripting
|
CVE-2016-2104
|
2024-11-21 11:47 |
2017-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267414
|
6.1 |
MEDIUM
Network
|
blackberry
|
blackberry_enterprise_service
|
Multiple cross-site scripting (XSS) vulnerabilities in BlackBerry Enterprise Server 12 (BES12) Self-Service before 12.4 allow remote attackers to inject arbitrary web script or HTML via the locale pa…
|
CWE-79
Cross-site Scripting
|
CVE-2016-1915
|
2024-11-21 11:47 |
2017-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267415
|
8.8 |
HIGH
Network
|
blackberry
|
blackberry_enterprise_service
|
Multiple SQL injection vulnerabilities in the com.rim.mdm.ui.server.ImageServlet servlet in BlackBerry Enterprise Server 12 (BES12) Self-Service before 12.4 allow remote attackers to execute arbitrar…
|
CWE-89
SQL Injection
|
CVE-2016-1914
|
2024-11-21 11:47 |
2017-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267416
|
9.8 |
CRITICAL
Network
|
openbsd debian oracle redhat
|
openssh debian_linux linux enterprise_linux_desktop enterprise_linux_server_aus enterprise_linux_workstation enterprise_linux_server_tus enterprise_linux_server enterprise_lin…
|
The client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding and relies on the local X11 server for access-control decisions, which allows remote X11 clients to t…
|
CWE-287
Improper Authentication
|
CVE-2016-1908
|
2024-11-21 11:47 |
2017-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267417
|
7.8 |
HIGH
Local
|
freebsd
|
freebsd
|
Integer overflow in the bhyve hypervisor in FreeBSD 10.1, 10.2, 10.3, and 11.0 when configured with a large amount of guest memory, allows local users to gain privilege via a crafted device descripto…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2016-1889
|
2024-11-21 11:47 |
2017-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267418
|
7.5 |
HIGH
Network
|
freebsd
|
freebsd
|
The telnetd service in FreeBSD 9.3, 10.1, 10.2, 10.3, and 11.0 allows remote attackers to inject arguments to login and bypass authentication via vectors involving a "sequence of memory allocation fa…
|
CWE-287
Improper Authentication
|
CVE-2016-1888
|
2024-11-21 11:47 |
2017-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267419
|
7.8 |
HIGH
Local
|
freebsd
|
freebsd
|
The issetugid system call in the Linux compatibility layer in FreeBSD 9.3, 10.1, and 10.2 allows local users to gain privilege via unspecified vectors.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-1883
|
2024-11-21 11:47 |
2017-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267420
|
7.8 |
HIGH
Local
|
freebsd
|
freebsd
|
The kernel in FreeBSD 9.3, 10.1, and 10.2 allows local users to cause a denial of service (crash) or potentially gain privilege via a crafted Linux compatibility layer setgroups system call.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-1881
|
2024-11-21 11:47 |
2017-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|