|
266701
|
8.0 |
HIGH
Network
|
symantec
|
endpoint_protection_manager
|
Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated users to discover the PHP JSESSIONID value via unspecified vectors.
|
CWE-200
Information Exposure
|
CVE-2016-3651
|
2024-11-21 11:50 |
2016-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266702
|
8.8 |
HIGH
Network
|
symantec
|
endpoint_protection_manager
|
Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated users to discover credentials via a brute-force attack.
|
CWE-200 CWE-254
Information Exposure 7PK - Security Features
|
CVE-2016-3650
|
2024-11-21 11:50 |
2016-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266703
|
4.3 |
MEDIUM
Network
|
symantec
|
endpoint_protection_manager
|
Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated administrators to enumerate administrator accounts via modified GET requests.
|
CWE-200
Information Exposure
|
CVE-2016-3649
|
2024-11-21 11:50 |
2016-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266704
|
8.8 |
HIGH
Network
|
symantec
|
endpoint_protection_manager
|
Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated users to bypass the Authentication Lock protection mechanism, and conduct brute-force password-guessing att…
|
CWE-200 CWE-254
Information Exposure 7PK - Security Features
|
CVE-2016-3648
|
2024-11-21 11:50 |
2016-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266705
|
7.7 |
HIGH
Network
|
symantec
|
endpoint_protection_manager
|
Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated users to conduct server-side request forgery (SSRF) attacks, and trigger network traffic to arbitrary intra…
|
NVD-CWE-Other
|
CVE-2016-3647
|
2024-11-21 11:50 |
2016-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266706
|
8.4 |
HIGH
Local
|
symantec
|
norton_security protection_engine advanced_threat_protection norton_bootable_removal_tool data_center_security_server protection_for_sharepoint_servers message_gateway_for_service_p…
|
The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SE…
|
CWE-20
Improper Input Validation
|
CVE-2016-3646
|
2024-11-21 11:50 |
2016-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266707
|
9.8 |
CRITICAL
Network
|
symantec
|
norton_security protection_engine advanced_threat_protection norton_bootable_removal_tool data_center_security_server protection_for_sharepoint_servers message_gateway_for_service_p…
|
Integer overflow in the TNEF unpacker in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web …
|
CWE-189
Numeric Errors
|
CVE-2016-3645
|
2024-11-21 11:50 |
2016-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266708
|
8.4 |
HIGH
Local
|
symantec
|
norton_security protection_engine advanced_threat_protection norton_bootable_removal_tool data_center_security_server protection_for_sharepoint_servers message_gateway_for_service_p…
|
The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SE…
|
CWE-20
Improper Input Validation
|
CVE-2016-3644
|
2024-11-21 11:50 |
2016-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266709
|
7.1 |
HIGH
Local
|
linux
|
linux_kernel
|
The msr_mtrr_valid function in arch/x86/kvm/mtrr.c in the Linux kernel before 4.6.1 supports MSR 0x2f8, which allows guest OS users to read or write to the kvm_arch_vcpu data structure, and consequen…
|
CWE-284
Improper Access Control
|
CVE-2016-3713
|
2024-11-21 11:50 |
2016-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266710
|
8.1 |
HIGH
Network
|
linux redhat novell
|
linux_kernel-rt enterprise_linux_for_real_time enterprise_linux_for_real_time_for_nfv suse_linux_enterprise_real_time_extension
|
The icmp_check_sysrq function in net/ipv4/icmp.c in the kernel.org projects/rt patches for the Linux kernel, as used in the kernel-rt package before 3.10.0-327.22.1 in Red Hat Enterprise Linux for Re…
|
CWE-284
Improper Access Control
|
CVE-2016-3707
|
2024-11-21 11:50 |
2016-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|