|
265351
|
5.3 |
MEDIUM
Network
|
kmc_controls
|
bac-5051e_firmware
|
KMC Controls BAC-5051E devices with firmware before E0.2.0.2 allow remote attackers to bypass intended access restrictions and read a configuration file via unspecified vectors.
|
CWE-310 CWE-284
Cryptographic Issues Improper Access Control
|
CVE-2016-4495
|
2024-11-21 11:52 |
2016-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265352
|
8.8 |
HIGH
Network
|
kmc_controls
|
bac-5051e_firmware
|
Cross-site request forgery (CSRF) vulnerability on KMC Controls BAC-5051E devices with firmware before E0.2.0.2 allows remote attackers to hijack the authentication of unspecified victims for request…
|
CWE-352
Origin Validation Error
|
CVE-2016-4494
|
2024-11-21 11:52 |
2016-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265353
|
7.1 |
HIGH
Local
|
debian canonical xmlsoft
|
debian_linux ubuntu_linux libxml2
|
XML external entity (XXE) vulnerability in the xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.4, when not in validating mode, allows context-dependent attackers to read arbitra…
|
CWE-20
Improper Input Validation
|
CVE-2016-4449
|
2024-11-21 11:52 |
2016-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265354
|
9.8 |
CRITICAL
Network
|
hp apple xmlsoft redhat slackware oracle tenable mcafee
|
icewall_federation_agent watchos mac_os_x libxml2 icloud iphone_os enterprise_linux_desktop enterprise_linux_server_aus enterprise_linux_workstation enterprise_linux_server…
|
Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors.
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2016-4448
|
2024-11-21 11:52 |
2016-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265355
|
7.5 |
HIGH
Network
|
hp canonical debian oracle apple xmlsoft mcafee
|
icewall_federation_agent ubuntu_linux debian_linux vm_server itunes iphone_os tvos watchos mac_os_x libxml2 web_gateway
|
The xmlParseElementDecl function in parser.c in libxml2 before 2.9.4 allows context-dependent attackers to cause a denial of service (heap-based buffer underread and application crash) via a crafted …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-4447
|
2024-11-21 11:52 |
2016-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265356
|
9.1 |
CRITICAL
Network
|
trihedral
|
vtscada
|
Directory traversal vulnerability in the WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to read arbitrary files via a crafted pathname.
|
CWE-22
Path Traversal
|
CVE-2016-4532
|
2024-11-21 11:52 |
2016-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265357
|
9.1 |
CRITICAL
Network
|
trihedral
|
vtscada
|
The WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to bypass authentication and read arbitrary files via unspecified vectors.
|
CWE-287
Improper Authentication
|
CVE-2016-4510
|
2024-11-21 11:52 |
2016-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265358
|
7.5 |
HIGH
Network
|
f5
|
big-ip_application_acceleration_manager big-ip_advanced_firewall_manager big-ip_local_traffic_manager big-ip_analytics big-ip_global_traffic_manager big-ip_policy_enforcement_manager
|
Virtual servers in F5 BIG-IP 11.5.4, when SSL profiles are enabled, allow remote attackers to cause a denial of service (resource consumption and Traffic Management Microkernel restart) via an SSL al…
|
CWE-20
Improper Input Validation
|
CVE-2016-4545
|
2024-11-21 11:52 |
2016-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265359
|
7.5 |
HIGH
Network
|
canonical f5 debian
|
ubuntu_linux nginx debian_linux
|
os/unix/ngx_files.c in nginx before 1.10.1 and 1.11.x before 1.11.1 allows remote attackers to cause a denial of service (NULL pointer dereference and worker process crash) via a crafted request, inv…
|
CWE-476
NULL Pointer Dereference
|
CVE-2016-4450
|
2024-11-21 11:52 |
2016-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265360
|
9.8 |
CRITICAL
Network
|
imagemagick
|
imagemagick
|
The DrawImage function in MagickCore/draw.c in ImageMagick before 6.9.4-0 and 7.x before 7.0.1-2 makes an incorrect function call in attempting to locate the next token, which allows remote attackers…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-4564
|
2024-11-21 11:52 |
2016-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|