|
267281
|
4.7 |
MEDIUM
Local
|
google
|
android
|
In an ioctl handler in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, if a user supplies a value too large, then an out-of-bounds read occurs.
|
CWE-200
Information Exposure
|
CVE-2016-5858
|
2024-11-21 11:55 |
2017-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267282
|
4.7 |
MEDIUM
Local
|
google
|
android
|
In a driver in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, a user-supplied buffer is casted to a structure without checking if the source buffer is large enough.
|
CWE-200
Information Exposure
|
CVE-2016-5855
|
2024-11-21 11:55 |
2017-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267283
|
4.7 |
MEDIUM
Local
|
google
|
android
|
In a driver in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, kernel heap memory can be exposed to userspace.
|
CWE-200
Information Exposure
|
CVE-2016-5854
|
2024-11-21 11:55 |
2017-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267284
|
7.0 |
HIGH
Local
|
google
|
android
|
In an audio driver in all Qualcomm products with Android releases from CAF using the Linux kernel, when a sanity check encounters a length value not in the correct range, an error message is printed,…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-5853
|
2024-11-21 11:55 |
2017-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267285
|
5.9 |
MEDIUM
Network
|
ibm
|
emptoris_strategic_supply_management
|
IBM Emptoris Strategic Supply Management Platform 10.0 and 10.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security.…
|
CWE-200
Information Exposure
|
CVE-2016-6029
|
2024-11-21 11:55 |
2017-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267286
|
5.4 |
MEDIUM
Network
|
ibm
|
emptoris_strategic_supply_management
|
IBM Emptoris Strategic Supply Management Platform 10.0 and 10.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering t…
|
CWE-79
Cross-site Scripting
|
CVE-2016-6021
|
2024-11-21 11:55 |
2017-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267287
|
5.4 |
MEDIUM
Network
|
ibm
|
emptoris_strategic_supply_management emptoris_supplier_lifecycle_management
|
IBM Emptoris Supplier Lifecycle Management 10.0.x and 10.1.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the …
|
CWE-79
Cross-site Scripting
|
CVE-2016-6121
|
2024-11-21 11:55 |
2017-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267288
|
7.5 |
HIGH
Network
|
trendmicro
|
control_manager
|
Information Disclosure vulnerability in the Dashboard and Error Pages in Trend Micro Control Manager SP3 6.0.
|
CWE-200
Information Exposure
|
CVE-2016-6220
|
2024-11-21 11:55 |
2017-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267289
|
6.1 |
MEDIUM
Network
|
ektron
|
ektron_content_management_system
|
Cross-site scripting (XSS) vulnerability in Ektron Content Management System before 9.1.0.184SP3(9.1.0.184.3.127) allows remote attackers to inject arbitrary web script or HTML via the rptStatus para…
|
CWE-79
Cross-site Scripting
|
CVE-2016-6133
|
2024-11-21 11:55 |
2017-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267290
|
5.4 |
MEDIUM
Network
|
ibm
|
emptoris_strategic_supply_management
|
IBM Emptoris Supplier Lifecycle Management 10.1.0.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended …
|
CWE-79
Cross-site Scripting
|
CVE-2016-6118
|
2024-11-21 11:55 |
2017-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|