|
264851
|
6.5 |
MEDIUM
Network
|
freeipa oracle fedoraproject
|
freeipa linux fedora
|
The cert_revoke command in FreeIPA does not check for the "revoke certificate" permission, which allows remote authenticated users to revoke arbitrary certificates by leveraging the "retrieve certifi…
|
CWE-284
Improper Access Control
|
CVE-2016-5404
|
2024-11-21 11:54 |
2016-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264852
|
8.8 |
HIGH
Network
|
redhat
|
jboss_operations_network
|
The web console in Red Hat JBoss Operations Network (JON) before 3.3.7 does not properly authorize requests to add users with the super user role, which allows remote authenticated users to gain admi…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-5422
|
2024-11-21 11:54 |
2016-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264853
|
5.3 |
MEDIUM
Network
|
jose-php_project
|
jose-php
|
The RSA 1.5 algorithm implementation in the JOSE_JWE class in JWE.php in jose-php before 2.2.1 lacks the Random Filling protection mechanism, which makes it easier for remote attackers to obtain clea…
|
CWE-310 CWE-200
Cryptographic Issues Information Exposure
|
CVE-2016-5430
|
2024-11-21 11:54 |
2016-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264854
|
3.7 |
LOW
Network
|
jose-php_project
|
jose-php
|
jose-php before 2.2.1 does not use constant-time operations for HMAC comparison, which makes it easier for remote attackers to obtain sensitive information via a timing attack, related to JWE.php and…
|
CWE-200
Information Exposure
|
CVE-2016-5429
|
2024-11-21 11:54 |
2016-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264855
|
6.1 |
MEDIUM
Network
|
python
|
python
|
CRLF injection vulnerability in the HTTPConnection.putheader function in urllib2 and urllib in CPython (aka Python) before 2.7.10 and 3.x before 3.4.4 allows remote attackers to inject arbitrary HTTP…
|
CWE-113
HTTP Response Splitting
|
CVE-2016-5699
|
2024-11-21 11:54 |
2016-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264856
|
9.8 |
CRITICAL
Network
|
python
|
python
|
Integer overflow in the get_data function in zipimport.c in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 allows remote attackers to have unspecified impact via a negat…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2016-5636
|
2024-11-21 11:54 |
2016-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264857
|
8.8 |
HIGH
Network
|
nuuo netgear
|
nvrmini_2 readynas_surveillance
|
Stack-based buffer overflow in cgi-bin/cgi_main in NUUO NVRmini 2 1.7.6 through 3.0.0 and NETGEAR ReadyNAS Surveillance 1.1.2 allows remote authenticated users to execute arbitrary code via the sn pa…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-5680
|
2024-11-21 11:54 |
2016-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264858
|
8.8 |
HIGH
Network
|
nuuo netgear
|
nvrmini_2 readynas_surveillance
|
cgi-bin/cgi_main in NUUO NVRmini 2 1.7.6 through 3.0.0 and NETGEAR ReadyNAS Surveillance 1.1.2 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the sn param…
|
CWE-78
OS Command
|
CVE-2016-5679
|
2024-11-21 11:54 |
2016-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264859
|
9.8 |
CRITICAL
Network
|
nuuo
|
nvrmini_2 nvrsolo
|
NUUO NVRmini 2 1.0.0 through 3.0.0 and NUUO NVRsolo 1.0.0 through 3.0.0 have hardcoded root credentials, which allows remote attackers to obtain administrative access via unspecified vectors.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2016-5678
|
2024-11-21 11:54 |
2016-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264860
|
7.5 |
HIGH
Network
|
netgear nuuo
|
readynas_surveillance nvrmini_2 nvrsolo
|
NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 have a hardcoded qwe23622260 password for the nuuoeng account, which allows…
|
CWE-200
Information Exposure
|
CVE-2016-5677
|
2024-11-21 11:54 |
2016-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|