|
266861
|
7.9 |
HIGH
Local
|
hp
|
700_series_firmware 800_series_firmware z240_firmware z238_firmware zbook_firmware 1000_series_firmware elitebook_folio_1012_x2_g2
|
Sure Start on HP Commercial PCs 2015 allows local users to cause a denial of service (BIOS recovery failure) by leveraging administrative access.
|
CWE-284
Improper Access Control
|
CVE-2016-2243
|
2024-11-21 11:48 |
2016-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266862
|
9.8 |
CRITICAL
Network
|
openssl
|
openssl
|
The doapr_outch function in crypto/bio/b_print.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g does not verify that a certain memory allocation succeeds, which allows remote attackers to cau…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-2842
|
2024-11-21 11:48 |
2016-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266863
|
6.1 |
MEDIUM
Network
|
rockwellautomation
|
compactlogix_1769-l16er-bb1b_firmware compactlogix_1769-l18er-bb1b_firmware compactlogix_1769-l18erm-bb1b_firmware compactlogix_1769-l24er-qb1b_firmware compactlogix_1769-l24er-qbfc1b_fir…
|
Cross-site scripting (XSS) vulnerability in the web server in Rockwell Automation Allen-Bradley CompactLogix 1769-L* before 28.011+ allows remote attackers to inject arbitrary web script or HTML via …
|
CWE-79
Cross-site Scripting
|
CVE-2016-2279
|
2024-11-21 11:48 |
2016-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266864
|
7.2 |
HIGH
Network
|
schneider-electric
|
struxureware_building_operations_automation_server_as_firmware struxureware_building_operations_automation_server_as-p_firmware
|
Schneider Electric Struxureware Building Operations Automation Server AS 1.7 and earlier and AS-P 1.7 and earlier allows remote authenticated administrators to execute arbitrary OS commands by defeat…
|
CWE-284
Improper Access Control
|
CVE-2016-2278
|
2024-11-21 11:48 |
2016-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266865
|
6.8 |
MEDIUM
Network
|
phpmyadmin
|
phpmyadmin
|
The checkHTTP function in libraries/Config.class.php in phpMyAdmin 4.5.x before 4.5.5.1 does not verify X.509 certificates from api.github.com SSL servers, which allows man-in-the-middle attackers to…
|
CWE-20
Improper Input Validation
|
CVE-2016-2562
|
2024-11-21 11:48 |
2016-03-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266866
|
5.4 |
MEDIUM
Network
|
phpmyadmin
|
phpmyadmin
|
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.4.x before 4.4.15.5 and 4.5.x before 4.5.5.1 allow remote authenticated users to inject arbitrary web script or HTML via (1) normal…
|
CWE-79
Cross-site Scripting
|
CVE-2016-2561
|
2024-11-21 11:48 |
2016-03-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266867
|
6.1 |
MEDIUM
Network
|
phpmyadmin
|
phpmyadmin
|
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.15, 4.4.x before 4.4.15.5, and 4.5.x before 4.5.5.1 allow remote attackers to inject arbitrary web script or HTML…
|
CWE-79
Cross-site Scripting
|
CVE-2016-2560
|
2024-11-21 11:48 |
2016-03-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266868
|
5.4 |
MEDIUM
Network
|
phpmyadmin
|
phpmyadmin
|
Cross-site scripting (XSS) vulnerability in the format function in libraries/sql-parser/src/Utils/Error.php in the SQL parser in phpMyAdmin 4.5.x before 4.5.5.1 allows remote authenticated users to i…
|
CWE-79
Cross-site Scripting
|
CVE-2016-2559
|
2024-11-21 11:48 |
2016-03-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266869
|
5.9 |
MEDIUM
Network
|
wireshark
|
wireshark
|
The dissect_llrp_parameters function in epan/dissectors/packet-llrp.c in the LLRP dissector in Wireshark 1.12.x before 1.12.10 and 2.0.x before 2.0.2 does not limit the recursion depth, which allows …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-2532
|
2024-11-21 11:48 |
2016-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266870
|
5.9 |
MEDIUM
Network
|
wireshark
|
wireshark
|
Off-by-one error in epan/dissectors/packet-rsl.c in the RSL dissector in Wireshark 1.12.x before 1.12.10 and 2.0.x before 2.0.2 allows remote attackers to cause a denial of service (out-of-bounds rea…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-2531
|
2024-11-21 11:48 |
2016-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|