|
267311
|
9.8 |
CRITICAL
Network
|
lexmark
|
printer_firmware
|
Race condition in the initialization process on Lexmark printers with firmware ATL before ATL.02.049, CB before CB.02.049, PP before PP.02.049, and YK before YK.02.049 allows remote attackers to bypa…
|
CWE-264 CWE-254
Permissions, Privileges, and Access Controls 7PK - Security Features
|
CVE-2016-1896
|
2024-11-21 11:47 |
2016-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267312
|
6.1 |
MEDIUM
Network
|
greenbone fedoraproject
|
greenbone_security_assistant greenbone_os fedora
|
Cross-site scripting (XSS) vulnerability in the charts module in Greenbone Security Assistant (GSA) 6.x before 6.0.8 allows remote attackers to inject arbitrary web script or HTML via the aggregate_t…
|
CWE-79
Cross-site Scripting
|
CVE-2016-1926
|
2024-11-21 11:47 |
2016-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267313
|
7.6 |
HIGH
Network
|
harfbuzz_project google
|
harfbuzz chrome
|
Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6, as used in Google Chrome before 48.0.2564.82, allow attackers to cause a denial of service or possibly have other impact via crafted dat…
|
NVD-CWE-noinfo
|
CVE-2016-2052
|
2024-11-21 11:47 |
2016-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267314
|
9.8 |
CRITICAL
Network
|
google redhat
|
chrome enterprise_linux_desktop_supplementary enterprise_linux_server_supplementary enterprise_linux_workstation_supplementary enterprise_linux_server_supplementary_eus
|
Multiple unspecified vulnerabilities in Google V8 before 4.8.271.17, as used in Google Chrome before 48.0.2564.82, allow attackers to cause a denial of service or possibly have other impact via unkno…
|
NVD-CWE-noinfo
|
CVE-2016-2051
|
2024-11-21 11:47 |
2016-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267315
|
9.8 |
CRITICAL
Network
|
harman
|
amx_firmware
|
The setUpSubtleUserAccount function in /bin/bw on Harman AMX devices before 2016-01-20 has a hardcoded password for the 1MB@tMaN account, which makes it easier for remote attackers to obtain access v…
|
CWE-255
Credentials Management
|
CVE-2016-1984
|
2024-11-21 11:47 |
2016-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267316
|
9.3 |
CRITICAL
Network
|
sap
|
hana
|
The XS engine in SAP HANA allows remote attackers to spoof log entries in trace files and consequently cause a denial of service (disk consumption and process crash) via a crafted HTTP request, relat…
|
CWE-20
Improper Input Validation
|
CVE-2016-1929
|
2024-11-21 11:47 |
2016-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267317
|
9.8 |
CRITICAL
Network
|
sap
|
hana
|
Buffer overflow in the XS engine (hdbxsengine) in SAP HANA allows remote attackers to cause a denial of service or execute arbitrary code via a crafted HTTP request, related to JSON, aka SAP Security…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-1928
|
2024-11-21 11:47 |
2016-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267318
|
9.8 |
CRITICAL
Network
|
fedoraproject cgit_project
|
fedora cgit
|
Integer overflow in the authenticate_post function in CGit before 0.12 allows remote attackers to have unspecified impact via a large value in the Content-Length HTTP header, which triggers a buffer …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-1901
|
2024-11-21 11:47 |
2016-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267319
|
3.7 |
LOW
Network
|
fedoraproject cgit_project
|
fedora cgit
|
CRLF injection vulnerability in the cgit_print_http_headers function in ui-shared.c in CGit before 0.12 allows remote attackers with permission to write to a repository to inject arbitrary HTTP heade…
|
NVD-CWE-Other
|
CVE-2016-1900
|
2024-11-21 11:47 |
2016-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267320
|
3.7 |
LOW
Network
|
fedoraproject cgit_project
|
fedora cgit
|
CRLF injection vulnerability in the ui-blob handler in CGit before 0.12 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks or cross-site scripting (X…
|
NVD-CWE-Other
|
CVE-2016-1899
|
2024-11-21 11:47 |
2016-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|