|
266711
|
4.6 |
MEDIUM
Physics
|
novell linux
|
suse_linux_enterprise_module_for_public_cloud suse_linux_enterprise_server suse_linux_enterprise_live_patching suse_linux_enterprise_real_time_extension suse_linux_enterprise_desktop s…
|
The wacom_probe function in drivers/input/tablet/wacom_sys.c in the Linux kernel before 3.17 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system cr…
|
NVD-CWE-Other
|
CVE-2016-3139
|
2024-11-21 11:49 |
2016-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266712
|
8.4 |
HIGH
Local
|
novell linux
|
suse_linux_enterprise_module_for_public_cloud suse_linux_enterprise_server suse_linux_enterprise_live_patching suse_linux_enterprise_desktop suse_linux_enterprise_real_time_extension s…
|
The netfilter subsystem in the Linux kernel through 4.5.2 does not validate certain offset fields, which allows local users to gain privileges or cause a denial of service (heap memory corruption) vi…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-3134
|
2024-11-21 11:49 |
2016-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266713
|
9.8 |
CRITICAL
Network
|
apache
|
struts
|
XSLTResult in Apache Struts 2.x before 2.3.20.2, 2.3.24.x before 2.3.24.2, and 2.3.28.x before 2.3.28.1 allows remote attackers to execute arbitrary code via the stylesheet location parameter.
|
CWE-20
Improper Input Validation
|
CVE-2016-3082
|
2024-11-21 11:49 |
2016-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266714
|
8.1 |
HIGH
Network
|
apache oracle
|
struts siebel_e-billing
|
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via method: prefix, related to …
|
CWE-77
Command Injection
|
CVE-2016-3081
|
2024-11-21 11:49 |
2016-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266715
|
9.8 |
CRITICAL
Network
|
libgd debian fedoraproject canonical opensuse php
|
libgd debian_linux fedora ubuntu_linux opensuse php
|
Integer signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote attackers to cause a denial of service (crash) or potentially execute arbitrary code via crafted compressed g…
|
CWE-681
Incorrect Conversion between Numeric Types
|
CVE-2016-3074
|
2024-11-21 11:49 |
2016-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266716
|
6.1 |
MEDIUM
Network
|
blackberry
|
enterprise_server
|
Cross-site scripting (XSS) vulnerability in the Management Console in BlackBerry Enterprise Server (BES) 12 before 12.4.1 allows remote attackers to inject arbitrary web script or HTML via a crafted …
|
CWE-79
Cross-site Scripting
|
CVE-2016-3126
|
2024-11-21 11:49 |
2016-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266717
|
4.6 |
MEDIUM
Physics
|
lexmark
|
printer_firmware
|
Lexmark printers with firmware ATL before ATL.021.063, CB before CB.021.063, PP before PP.021.063, and YK before YK.021.063 mishandle Erase Printer Memory and Erase Hard Disk actions, which allows ph…
|
CWE-200
Information Exposure
|
CVE-2016-3145
|
2024-11-21 11:49 |
2016-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266718
|
7.5 |
HIGH
Network
|
opensuse cairographics
|
opensuse cairo
|
The fill_xrgb32_lerp_opaque_spans function in cairo-image-compositor.c in cairo before 1.14.2 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a neg…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-3190
|
2024-11-21 11:49 |
2016-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266719
|
6.4 |
MEDIUM
Network
|
oracle
|
agile_product_lifecycle_management_framework
|
Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.1.1, 9.3.1.2, 9.3.2, and 9.3.3 allows remote authenticated users to affect confidentiality and in…
|
NVD-CWE-noinfo
|
CVE-2016-3431
|
2024-11-21 11:49 |
2016-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266720
|
4.5 |
MEDIUM
Physics
|
oracle
|
retail_xstore_point_of_service
|
Unspecified vulnerability in the Oracle Retail Xstore Point of Service component in Oracle Retail Applications 5.0, 5.5, 6.0, 6.5, 7.0, and 7.1 allows remote authenticated users to affect confidentia…
|
NVD-CWE-noinfo
|
CVE-2016-3429
|
2024-11-21 11:49 |
2016-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|