|
266951
|
5.5 |
MEDIUM
Local
|
samsung
|
galaxy_s6_firmware galaxy_note_3_firmware
|
The getURL function in drivers/secfilter/urlparser.c in secfilter in the Samsung kernel for Android on SM-N9005 build N9005XXUGBOB6 (Note 3) and SM-G920F build G920FXXU2COH2 (Galaxy S6) devices allow…
|
CWE-476
NULL Pointer Dereference
|
CVE-2016-2036
|
2024-11-21 11:47 |
2017-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266952
|
6.1 |
MEDIUM
Network
|
redhat
|
satellite
|
Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Satellite 5 allow remote attackers to inject arbitrary web script or HTML via (1) the label parameter to admin/BunchDetail.do; (2) the p…
|
CWE-79
Cross-site Scripting
|
CVE-2016-2104
|
2024-11-21 11:47 |
2017-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266953
|
6.1 |
MEDIUM
Network
|
blackberry
|
blackberry_enterprise_service
|
Multiple cross-site scripting (XSS) vulnerabilities in BlackBerry Enterprise Server 12 (BES12) Self-Service before 12.4 allow remote attackers to inject arbitrary web script or HTML via the locale pa…
|
CWE-79
Cross-site Scripting
|
CVE-2016-1915
|
2024-11-21 11:47 |
2017-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266954
|
8.8 |
HIGH
Network
|
blackberry
|
blackberry_enterprise_service
|
Multiple SQL injection vulnerabilities in the com.rim.mdm.ui.server.ImageServlet servlet in BlackBerry Enterprise Server 12 (BES12) Self-Service before 12.4 allow remote attackers to execute arbitrar…
|
CWE-89
SQL Injection
|
CVE-2016-1914
|
2024-11-21 11:47 |
2017-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266955
|
9.8 |
CRITICAL
Network
|
openbsd debian oracle redhat
|
openssh debian_linux linux enterprise_linux_desktop enterprise_linux_server_aus enterprise_linux_workstation enterprise_linux_server_tus enterprise_linux_server enterprise_lin…
|
The client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding and relies on the local X11 server for access-control decisions, which allows remote X11 clients to t…
|
CWE-287
Improper Authentication
|
CVE-2016-1908
|
2024-11-21 11:47 |
2017-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266956
|
7.8 |
HIGH
Local
|
freebsd
|
freebsd
|
Integer overflow in the bhyve hypervisor in FreeBSD 10.1, 10.2, 10.3, and 11.0 when configured with a large amount of guest memory, allows local users to gain privilege via a crafted device descripto…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2016-1889
|
2024-11-21 11:47 |
2017-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266957
|
7.5 |
HIGH
Network
|
freebsd
|
freebsd
|
The telnetd service in FreeBSD 9.3, 10.1, 10.2, 10.3, and 11.0 allows remote attackers to inject arguments to login and bypass authentication via vectors involving a "sequence of memory allocation fa…
|
CWE-287
Improper Authentication
|
CVE-2016-1888
|
2024-11-21 11:47 |
2017-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266958
|
7.8 |
HIGH
Local
|
freebsd
|
freebsd
|
The issetugid system call in the Linux compatibility layer in FreeBSD 9.3, 10.1, and 10.2 allows local users to gain privilege via unspecified vectors.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-1883
|
2024-11-21 11:47 |
2017-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266959
|
7.8 |
HIGH
Local
|
freebsd
|
freebsd
|
The kernel in FreeBSD 9.3, 10.1, and 10.2 allows local users to cause a denial of service (crash) or potentially gain privilege via a crafted Linux compatibility layer setgroups system call.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-1881
|
2024-11-21 11:47 |
2017-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266960
|
7.8 |
HIGH
Local
|
freebsd
|
freebsd
|
The Linux compatibility layer in the kernel in FreeBSD 9.3, 10.1, and 10.2 allows local users to read portions of kernel memory and potentially gain privilege via unspecified vectors, related to "han…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-1880
|
2024-11-21 11:47 |
2017-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|