|
266811
|
7.8 |
HIGH
Local
|
lenovo
|
fingerprint_manager touch_fingerprint
|
Lenovo Fingerprint Manager before 8.01.57 and Touch Fingerprint before 1.00.08 use weak ACLs for unspecified (1) services and (2) files, which allows local users to gain privileges by invalidating lo…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-2393
|
2024-11-21 11:48 |
2016-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266812
|
3.1 |
LOW
Network
|
djangoproject
|
django
|
The password hasher in contrib/auth/hashers.py in Django before 1.8.10 and 1.9.x before 1.9.3 allows remote attackers to enumerate users via a timing attack involving login requests.
|
CWE-200
Information Exposure
|
CVE-2016-2513
|
2024-11-21 11:48 |
2016-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266813
|
7.4 |
HIGH
Network
|
djangoproject
|
django
|
The utils.http.is_safe_url function in Django before 1.8.10 and 1.9.x before 1.9.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks or possibly conduct cr…
|
CWE-79
Cross-site Scripting
|
CVE-2016-2512
|
2024-11-21 11:48 |
2016-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266814
|
7.5 |
HIGH
Network
|
perl debian oracle opensuse canonical
|
perl debian_linux solaris database_server communications_billing_and_revenue_management enterprise_manager_base_platform configuration_manager timesten_in-memory_database open…
|
Perl might allow context-dependent attackers to bypass the taint protection mechanism in a child process via duplicate environment variables in envp.
|
CWE-20
Improper Input Validation
|
CVE-2016-2381
|
2024-11-21 11:48 |
2016-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266815
|
9.8 |
CRITICAL
Network
|
suse opensuse git-scm
|
openstack_cloud linux_enterprise_software_development_kit linux_enterprise_server linux_enterprise_debuginfo leap opensuse suse_linux_enterprise_server git
|
Integer overflow in Git before 2.7.4 allows remote attackers to execute arbitrary code via a (1) long filename or (2) many nested trees, which triggers a heap-based buffer overflow.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-2324
|
2024-11-21 11:48 |
2016-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266816
|
9.8 |
CRITICAL
Network
|
suse opensuse git-scm
|
openstack_cloud linux_enterprise_software_development_kit linux_enterprise_server linux_enterprise_debuginfo leap opensuse suse_linux_enterprise_server git
|
revision.c in git before 2.7.4 uses an incorrect integer data type, which allows remote attackers to execute arbitrary code via a (1) long filename or (2) many nested trees, leading to a heap-based b…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-2315
|
2024-11-21 11:48 |
2016-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266817
|
9.8 |
CRITICAL
Network
|
debian opensuse cypherpunks
|
debian_linux leap opensuse libotr
|
Integer overflow in proto.c in libotr before 4.1.1 on 64-bit platforms allows remote attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via a s…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-2851
|
2024-11-21 11:48 |
2016-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266818
|
6.1 |
MEDIUM
Network
|
citrix
|
xenmobile_server
|
Cross-site scripting (XSS) vulnerability in the Web User Interface in Citrix XenMobile Server 10.0, 10.1 before Rolling Patch 4, and 10.3 before Rolling Patch 1 allows remote attackers to inject arbi…
|
CWE-79
Cross-site Scripting
|
CVE-2016-2789
|
2024-11-21 11:48 |
2016-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266819
|
9.8 |
CRITICAL
Network
|
9bis simon_tatham
|
kitty putty
|
Stack-based buffer overflow in the SCP command-line utility in PuTTY before 0.67 and KiTTY 0.66.6.3 and earlier allows remote servers to cause a denial of service (stack memory corruption) or execute…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-2563
|
2024-11-21 11:48 |
2016-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266820
|
6.1 |
MEDIUM
Network
|
debian websvn
|
debian_linux websvn
|
Cross-site scripting (XSS) vulnerability in WebSVN 2.3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the path parameter to log.php.
|
CWE-79
Cross-site Scripting
|
CVE-2016-2511
|
2024-11-21 11:48 |
2016-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|