|
265111
|
7.5 |
HIGH
Network
|
mozilla debian redhat suse avaya
|
nss debian_linux enterprise_linux linux_enterprise_server call_management_system breeze_platform iq aura_application_server_5300 aura_application_enablement_services aura_c…
|
A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote m…
|
CWE-476
NULL Pointer Dereference
|
CVE-2016-5285
|
2024-11-21 11:53 |
2019-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265112
|
3.3 |
LOW
Local
|
dovecot opensuse redhat
|
dovecot leap opensuse enterprise_linux
|
A postinstall script in the dovecot rpm allows local users to read the contents of newly created SSL/TLS key files.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2016-4983
|
2024-11-21 11:53 |
2019-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265113
|
9.1 |
CRITICAL
Network
|
google
|
chrome
|
browser/extensions/api/dial/dial_registry.cc in Google Chrome before 54.0.2840.98 on macOS, before 54.0.2840.99 on Windows, and before 54.0.2840.100 on Linux neglects to copy a device ID before an er…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2016-5202
|
2024-11-21 11:53 |
2019-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265114
|
5.4 |
MEDIUM
Network
|
f5
|
websafe_alert_server
|
Cross-Site-Scripting (XSS) vulnerabilities in F5 WebSafe Dashboard 3.9.5 and earlier, aka F5 WebSafe Alert Server, allow privileged authenticated users to inject arbitrary web script or HTML when cre…
|
CWE-79
Cross-site Scripting
|
CVE-2016-5236
|
2024-11-21 11:53 |
2019-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265115
|
6.1 |
MEDIUM
Network
|
f5
|
websafe_alert_server
|
A Cross Site Scripting (XSS) vulnerability in versions of F5 WebSafe Dashboard 3.9.x and earlier, aka F5 WebSafe Alert Server, allows an unauthenticated user to inject HTML via a crafted alert.
|
CWE-79
Cross-site Scripting
|
CVE-2016-5235
|
2024-11-21 11:53 |
2019-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265116
|
6.1 |
MEDIUM
Network
|
apache
|
http_server
|
Possible CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdir. This issue was mitigated by changes made in 2.4.25 and 2.2.32 which prohibit CR or LF injection into …
|
CWE-93
CRLF Injection
|
CVE-2016-4975
|
2024-11-21 11:53 |
2018-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265117
|
9.8 |
CRITICAL
Network
|
google
|
chrome_os
|
Chrome OS before 53.0.2785.144 allows remote attackers to execute arbitrary commands at boot.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-5179
|
2024-11-21 11:53 |
2018-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265118
|
9.8 |
CRITICAL
Network
|
apache
|
ws-xmlrpc
|
The Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote attackers to execute arbitrary code via a crafted serialized Java object in an <ex:serializable> element.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2016-5003
|
2024-11-21 11:53 |
2017-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265119
|
7.8 |
HIGH
Local
|
apache
|
xml-rpc
|
XML external entity (XXE) vulnerability in the Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote attackers to conduct server-side request forgery (SSRF) attacks v…
|
CWE-611
XXE
|
CVE-2016-5002
|
2024-11-21 11:53 |
2017-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265120
|
7.5 |
HIGH
Network
|
juniper
|
junose
|
Receipt of a specifically malformed IPv6 packet processed by the router may trigger a line card reset: processor exception 0x68616c74 (halt) in task: scheduler. The line card will reboot and recover …
|
CWE-19
Data Processing Errors
|
CVE-2016-4925
|
2024-11-21 11:53 |
2017-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|