|
265951
|
8.4 |
HIGH
Local
|
symantec
|
norton_security protection_engine advanced_threat_protection norton_bootable_removal_tool data_center_security_server protection_for_sharepoint_servers message_gateway_for_service_p…
|
The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SE…
|
CWE-20
Improper Input Validation
|
CVE-2016-3644
|
2024-11-21 11:50 |
2016-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265952
|
7.1 |
HIGH
Local
|
linux
|
linux_kernel
|
The msr_mtrr_valid function in arch/x86/kvm/mtrr.c in the Linux kernel before 4.6.1 supports MSR 0x2f8, which allows guest OS users to read or write to the kvm_arch_vcpu data structure, and consequen…
|
CWE-284
Improper Access Control
|
CVE-2016-3713
|
2024-11-21 11:50 |
2016-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265953
|
8.1 |
HIGH
Network
|
linux redhat novell
|
linux_kernel-rt enterprise_linux_for_real_time enterprise_linux_for_real_time_for_nfv suse_linux_enterprise_real_time_extension
|
The icmp_check_sysrq function in net/ipv4/icmp.c in the kernel.org projects/rt patches for the Linux kernel, as used in the kernel-rt package before 3.10.0-327.22.1 in Red Hat Enterprise Linux for Re…
|
CWE-284
Improper Access Control
|
CVE-2016-3707
|
2024-11-21 11:50 |
2016-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265954
|
9.8 |
CRITICAL
Network
|
solarwinds
|
virtualization_manager
|
The RMI service in SolarWinds Virtualization Manager 6.3.1 and earlier allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collec…
|
NVD-CWE-Other
|
CVE-2016-3642
|
2024-11-21 11:50 |
2016-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265955
|
5.3 |
MEDIUM
Network
|
f5
|
big-ip_access_policy_manager big-ip_edge_gateway
|
Open redirect vulnerability in F5 BIG-IP APM 11.2.1, 11.4.x, 11.5.x, and 11.6.x before 11.6.0 HF6 and Edge Gateway 11.2.1, when using multi-domain single sign-on (SSO), allows remote attackers to red…
|
NVD-CWE-Other
|
CVE-2016-3687
|
2024-11-21 11:50 |
2016-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265956
|
8.1 |
HIGH
Network
|
redhat libndp debian canonical
|
enterprise_linux_desktop enterprise_linux_server_aus enterprise_linux_workstation enterprise_linux_server enterprise_linux_hpc_node enterprise_linux_server_eus enterprise_linux_hpc_…
|
libndp before 1.6, as used in NetworkManager, does not properly validate the origin of Neighbor Discovery Protocol (NDP) messages, which allows remote attackers to conduct man-in-the-middle attacks o…
|
CWE-284
Improper Access Control
|
CVE-2016-3698
|
2024-11-21 11:50 |
2016-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265957
|
6.5 |
MEDIUM
Network
|
huawei
|
wear_app hilink_app
|
The Huawei Wear App application before 15.0.0.307 for Android does not validate SSL certificates, which allows local users to have unspecified impact via unknown vectors, aka HWPSIRT-2016-03008.
|
CWE-254 CWE-345
7PK - Security Features Insufficient Verification of Data Authenticity
|
CVE-2016-3677
|
2024-11-21 11:50 |
2016-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265958
|
6.1 |
MEDIUM
Network
|
liferay
|
liferay_portal
|
Cross-site scripting (XSS) vulnerability in users.jsp in the Profile Search functionality in Liferay before 7.0.0 CE RC1 allows remote attackers to inject arbitrary web script or HTML via the FirstNa…
|
CWE-79
Cross-site Scripting
|
CVE-2016-3670
|
2024-11-21 11:50 |
2016-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265959
|
9.8 |
CRITICAL
Network
|
fedoraproject fasterxml
|
fedora jackson-dataformat-xml
|
XML external entity (XXE) vulnerability in XmlMapper in the Data format extension for Jackson (aka jackson-dataformat-xml) allows attackers to have unspecified impact via unknown vectors.
|
NVD-CWE-noinfo
|
CVE-2016-3720
|
2024-11-21 11:50 |
2016-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265960
|
7.5 |
HIGH
Network
|
opensuse gnu
|
opensuse glibc
|
Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo.c in the GNU C Library (aka glibc or libc6) allows remote attackers to cause a denial of service (crash) via vecto…
|
CWE-20
Improper Input Validation
|
CVE-2016-3706
|
2024-11-21 11:50 |
2016-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|