|
265471
|
7.5 |
HIGH
Network
|
apache
|
http_server
|
The Apache HTTP Server 2.4.18 through 2.4.20, when mod_http2 and mod_ssl are enabled, does not properly recognize the "SSLVerifyClient require" directive for HTTP/2 request authorization, which allow…
|
CWE-284
Improper Access Control
|
CVE-2016-4979
|
2024-11-21 11:53 |
2016-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265472
|
6.1 |
MEDIUM
Network
|
phpmyadmin opensuse
|
phpmyadmin opensuse
|
Cross-site scripting (XSS) vulnerability in phpMyAdmin 4.4.x before 4.4.15.6 and 4.6.x before 4.6.2 allows remote attackers to inject arbitrary web script or HTML via special characters that are mish…
|
CWE-79
Cross-site Scripting
|
CVE-2016-5099
|
2024-11-21 11:53 |
2016-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265473
|
5.3 |
MEDIUM
Network
|
phpmyadmin opensuse
|
phpmyadmin opensuse
|
Directory traversal vulnerability in libraries/error_report.lib.php in phpMyAdmin before 4.6.2-prerelease allows remote attackers to determine the existence of arbitrary files by triggering an error.
|
CWE-22
Path Traversal
|
CVE-2016-5098
|
2024-11-21 11:53 |
2016-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265474
|
5.3 |
MEDIUM
Network
|
opensuse phpmyadmin
|
opensuse phpmyadmin
|
phpMyAdmin before 4.6.2 places tokens in query strings and does not arrange for them to be stripped before external navigation, which allows remote attackers to obtain sensitive information by readin…
|
CWE-200
Information Exposure
|
CVE-2016-5097
|
2024-11-21 11:53 |
2016-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265475
|
7.5 |
HIGH
Network
|
ntp oracle novell suse opensuse
|
ntp solaris suse_manager linux_enterprise_server openstack_cloud manager_proxy linux_enterprise_desktop leap opensuse
|
ntpd in NTP before 4.2.8p8 allows remote attackers to cause a denial of service (daemon crash) via a crypto-NAK packet. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-1547.
|
CWE-476
NULL Pointer Dereference
|
CVE-2016-4957
|
2024-11-21 11:53 |
2016-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265476
|
5.3 |
MEDIUM
Network
|
ntp oracle novell suse opensuse siemens
|
ntp solaris suse_manager linux_enterprise_server openstack_cloud manager_proxy linux_enterprise_desktop leap opensuse simatic_net_cp_443-1_opc_ua_firmware
|
ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (interleaved-mode transition and time change) via a spoofed broadcast packet. NOTE: this vulnerability exists beca…
|
NVD-CWE-noinfo
|
CVE-2016-4956
|
2024-11-21 11:53 |
2016-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265477
|
5.9 |
MEDIUM
Network
|
ntp oracle novell suse opensuse siemens
|
ntp solaris suse_manager linux_enterprise_server openstack_cloud manager_proxy linux_enterprise_desktop leap opensuse simatic_net_cp_443-1_opc_ua_firmware
|
ntpd in NTP 4.x before 4.2.8p8, when autokey is enabled, allows remote attackers to cause a denial of service (peer-variable clearing and association outage) by sending (1) a spoofed crypto-NAK packe…
|
CWE-362
Race Condition
|
CVE-2016-4955
|
2024-11-21 11:53 |
2016-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265478
|
7.5 |
HIGH
Network
|
ntp oracle suse opensuse siemens
|
ntp solaris linux_enterprise_server openstack_cloud manager_proxy manager linux_enterprise_desktop leap opensuse simatic_net_cp_443-1_opc_ua_firmware tim_4r-ie_firmware<…
|
ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (ephemeral-association demobilization) by sending a spoofed crypto-NAK packet with incorrect authentication data at…
|
CWE-287
Improper Authentication
|
CVE-2016-4953
|
2024-11-21 11:53 |
2016-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265479
|
7.5 |
HIGH
Network
|
ntp oracle suse opensuse siemens
|
ntp solaris linux_enterprise_server openstack_cloud manager_proxy manager linux_enterprise_desktop leap opensuse simatic_net_cp_443-1_opc_ua_firmware tim_4r-ie_firmware<…
|
The process_packet function in ntp_proto.c in ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (peer-variable modification) by sending spoofed packets from many sou…
|
CWE-362
Race Condition
|
CVE-2016-4954
|
2024-11-21 11:53 |
2016-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265480
|
7.1 |
HIGH
Local
|
linux oracle canonical
|
linux_kernel linux ubuntu_linux
|
The IPT_SO_SET_REPLACE setsockopt implementation in the netfilter subsystem in the Linux kernel before 4.6 allows local users to cause a denial of service (out-of-bounds read) or possibly obtain sens…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-4998
|
2024-11-21 11:53 |
2016-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|