|
265071
|
6.1 |
MEDIUM
Network
|
phpmyadmin opensuse
|
phpmyadmin leap opensuse
|
setup/frames/index.inc.php in phpMyAdmin 4.0.10.x before 4.0.10.16, 4.4.15.x before 4.4.15.7, and 4.6.x before 4.6.3 allows remote attackers to conduct BBCode injection attacks against HTTP sessions …
|
CWE-74
Injection
|
CVE-2016-5701
|
2024-11-21 11:54 |
2016-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265072
|
4.3 |
MEDIUM
Network
|
symantec
|
endpoint_protection_manager
|
Directory traversal vulnerability in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated users to read arbitrary files in the web-root directory tree via unspe…
|
CWE-22
Path Traversal
|
CVE-2016-5307
|
2024-11-21 11:54 |
2016-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265073
|
5.3 |
MEDIUM
Network
|
symantec
|
endpoint_protection_manager
|
Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 does not properly implement the HSTS protection mechanism, which makes it easier for remote attackers to obtain sensitive information b…
|
CWE-200 CWE-254
Information Exposure 7PK - Security Features
|
CVE-2016-5306
|
2024-11-21 11:54 |
2016-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265074
|
5.4 |
MEDIUM
Network
|
symantec
|
endpoint_protection_manager
|
Multiple cross-site scripting (XSS) vulnerabilities in management scripts in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allow remote authenticated users to inject arbitrary web s…
|
CWE-79
Cross-site Scripting
|
CVE-2016-5305
|
2024-11-21 11:54 |
2016-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265075
|
6.8 |
MEDIUM
Network
|
symantec
|
endpoint_protection_manager
|
Open redirect vulnerability in a report-routing component in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated users to redirect users to arbitrary web sites…
|
NVD-CWE-Other
|
CVE-2016-5304
|
2024-11-21 11:54 |
2016-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265076
|
7.5 |
HIGH
Network
|
canonical haproxy
|
ubuntu_linux haproxy
|
HAproxy 1.6.x before 1.6.6, when a deny comes from a reqdeny rule, allows remote attackers to cause a denial of service (uninitialized memory access and crash) or possibly have unspecified other impa…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-5360
|
2024-11-21 11:54 |
2016-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265077
|
7.5 |
HIGH
Network
|
opensuse arvidn
|
leap opensuse libtorrent
|
The parse_chunk_header function in libtorrent before 1.1.1 allows remote attackers to cause a denial of service (crash) via a crafted (1) HTTP response or possibly a (2) UPnP broadcast.
|
CWE-20
Improper Input Validation
|
CVE-2016-5301
|
2024-11-21 11:54 |
2016-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265078
|
8.2 |
HIGH
Local
|
lenovo
|
bios_efi_driver
|
Lenovo BIOS EFI Driver allows local administrators to execute arbitrary code with System Management Mode (SMM) privileges via unspecified vectors.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-5729
|
2024-11-21 11:54 |
2016-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265079
|
7.5 |
HIGH
Network
|
huawei
|
ar3200_firmware
|
Memory leak in Huawei AR3200 before V200R007C00SPC900 allows remote attackers to cause a denial of service (memory consumption) via a large number of crafted Multiprotocol Label Switching (MPLS) pack…
|
CWE-399
Resource Management Errors
|
CVE-2016-5368
|
2024-11-21 11:54 |
2016-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265080
|
6.3 |
MEDIUM
Local
|
debian linux
|
debian_linux linux_kernel
|
Race condition in the vop_ioctl function in drivers/misc/mic/vop/vop_vringh.c in the MIC VOP driver in the Linux kernel before 4.6.1 allows local users to obtain sensitive information from kernel mem…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-5728
|
2024-11-21 11:54 |
2016-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|