|
266611
|
7.5 |
HIGH
Network
|
fonality
|
hud_web fonality
|
The Chrome HUDweb plugin before 2016-05-05 for Fonality (previously trixbox Pro) 12.6 through 14.1i uses the same hardcoded private key across different customers' installations, which allows remote …
|
CWE-310 NVD-CWE-Other
Cryptographic Issues
|
CVE-2016-2364
|
2024-11-21 11:48 |
2016-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266612
|
7.8 |
HIGH
Local
|
fonality
|
fonality
|
Fonality (previously trixbox Pro) 12.6 through 14.1i before 2016-06-01 uses weak permissions for the /var/www/rpc/surun script, which allows local users to obtain root access for unspecified command …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-2363
|
2024-11-21 11:48 |
2016-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266613
|
9.8 |
CRITICAL
Network
|
fonality
|
fonality
|
Fonality (previously trixbox Pro) 12.6 through 14.1i before 2016-06-01 has a hardcoded password for the FTP account, which allows remote attackers to obtain access via a (1) FTP or (2) SSH connection.
|
NVD-CWE-Other
|
CVE-2016-2362
|
2024-11-21 11:48 |
2016-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266614
|
6.0 |
MEDIUM
Local
|
qemu canonical
|
qemu ubuntu_linux
|
The ne2000_receive function in the NE2000 NIC emulation support (hw/net/ne2000.c) in QEMU before 2.5.1 allows local guest OS administrators to cause a denial of service (infinite loop and QEMU proces…
|
CWE-20
Improper Input Validation
|
CVE-2016-2841
|
2024-11-21 11:48 |
2016-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266615
|
7.1 |
HIGH
Local
|
qemu
|
qemu
|
Multiple integer overflows in the USB Net device emulator (hw/usb/dev-network.c) in QEMU before 2.5.1 allow local guest OS administrators to cause a denial of service (QEMU process crash) or obtain s…
|
CWE-189
Numeric Errors
|
CVE-2016-2538
|
2024-11-21 11:48 |
2016-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266616
|
6.5 |
MEDIUM
Local
|
qemu canonical
|
qemu ubuntu_linux
|
The is_rndis function in the USB Net device emulator (hw/usb/dev-network.c) in QEMU before 2.5.1 does not properly validate USB configuration descriptor objects, which allows local guest OS administr…
|
NVD-CWE-Other
|
CVE-2016-2392
|
2024-11-21 11:48 |
2016-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266617
|
5.0 |
MEDIUM
Local
|
qemu canonical debian
|
qemu ubuntu_linux debian_linux
|
The ohci_bus_start function in the USB OHCI emulation support (hw/usb/hcd-ohci.c) in QEMU allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process …
|
CWE-476
NULL Pointer Dereference
|
CVE-2016-2391
|
2024-11-21 11:48 |
2016-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266618
|
8.8 |
HIGH
Network
|
canonical opensuse mozilla novell
|
ubuntu_linux leap opensuse network_security_services firefox suse_linux_enterprise_server suse_linux_enterprise_desktop suse_linux_enterprise_software_development_kit
|
Mozilla Network Security Services (NSS) before 3.23, as used in Mozilla Firefox before 47.0, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly…
|
NVD-CWE-noinfo
|
CVE-2016-2834
|
2024-11-21 11:48 |
2016-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266619
|
6.1 |
MEDIUM
Network
|
opensuse mozilla canonical
|
leap opensuse firefox ubuntu_linux
|
Mozilla Firefox before 47.0 ignores Content Security Policy (CSP) directives for cross-domain Java applets, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks vi…
|
CWE-79 CWE-254
Cross-site Scripting 7PK - Security Features
|
CVE-2016-2833
|
2024-11-21 11:48 |
2016-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266620
|
4.3 |
MEDIUM
Network
|
canonical mozilla opensuse
|
ubuntu_linux firefox leap opensuse
|
Mozilla Firefox before 47.0 allows remote attackers to discover the list of disabled plugins via a fingerprinting attack involving Cascading Style Sheets (CSS) pseudo-classes.
|
CWE-200
Information Exposure
|
CVE-2016-2832
|
2024-11-21 11:48 |
2016-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|