|
264571
|
5.9 |
MEDIUM
Network
|
intel hp lenovo
|
ethernet_controller_x710_firmware ethernet_controller_xl710_firmware proliant_xl260a_g9_server ethernet_10gb_2-port_562sfp\+ ethernet_10gb_4-port_563sfp\+ ethernet_10gb_2-port_562flr-s…
|
A Denial of Service in Intel Ethernet Controller's X710/XL710 with Non-Volatile Memory Images before version 5.05 allows a remote attacker to stop the controller from processing network traffic worki…
|
CWE-20
Improper Input Validation
|
CVE-2016-8106
|
2024-11-21 11:58 |
2017-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264572
|
4.4 |
MEDIUM
Local
|
mcafee
|
security_information_and_event_management
|
Authentication bypass vulnerability in Enterprise Security Manager (ESM) and License Manager (LM) in Intel Security McAfee Security Information and Event Management (SIEM) 9.6.0 MR3 allows an adminis…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-8006
|
2024-11-21 11:58 |
2017-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264573
|
3.7 |
LOW
Network
|
dotclear
|
dotclear
|
Dotclear before 2.10.3, when the Host header is not part of the web server routing process, allows remote attackers to modify the password reset address link via the HTTP Host header.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-7903
|
2024-11-21 11:58 |
2017-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264574
|
8.8 |
HIGH
Network
|
dotclear
|
dotclear
|
Unrestricted file upload vulnerability in the fileUnzip->unzip method in Dotclear before 2.10.3 allows remote authenticated users with permissions to manage media items to execute arbitrary code by u…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2016-7902
|
2024-11-21 11:58 |
2017-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264575
|
5.4 |
MEDIUM
Network
|
vmware
|
esxi
|
Cross-site scripting (XSS) vulnerability in the Host Client in VMware vSphere Hypervisor (aka ESXi) 5.5 and 6.0 allows remote authenticated users to inject arbitrary web script or HTML via a crafted …
|
CWE-79
Cross-site Scripting
|
CVE-2016-7463
|
2024-11-21 11:58 |
2016-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264576
|
8.5 |
HIGH
Network
|
vmware
|
vrealize_operations
|
The Suite REST API in VMware vRealize Operations (aka vROps) 6.x before 6.4.0 allows remote authenticated users to write arbitrary content to files or rename files via a crafted DiskFileItem in a rel…
|
CWE-264 CWE-749
Permissions, Privileges, and Access Controls Exposed Dangerous Method or Function
|
CVE-2016-7462
|
2024-11-21 11:58 |
2016-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264577
|
8.8 |
HIGH
Local
|
vmware
|
fusion fusion_pro workstation_player workstation_pro
|
The drag-and-drop (aka DnD) function in VMware Workstation Pro 12.x before 12.5.2 and VMware Workstation Player 12.x before 12.5.2 and VMware Fusion and Fusion Pro 8.x before 8.5.2 allows guest OS us…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-7461
|
2024-11-21 11:58 |
2016-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264578
|
9.1 |
CRITICAL
Network
|
vmware
|
vrealize_automation
|
The Single Sign-On feature in VMware vCenter Server 5.5 before U3e and 6.0 before U2a and vRealize Automation 6.x before 6.2.5 allows remote attackers to read arbitrary files or cause a denial of ser…
|
CWE-611
XXE
|
CVE-2016-7460
|
2024-11-21 11:58 |
2016-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264579
|
7.7 |
HIGH
Network
|
vmware
|
vcenter_server
|
VMware vCenter Server 5.5 before U3e and 6.0 before U2a allows remote authenticated users to read arbitrary files via a (1) Log Browser, (2) Distributed Switch setup, or (3) Content Library XML docum…
|
CWE-611
XXE
|
CVE-2016-7459
|
2024-11-21 11:58 |
2016-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264580
|
5.8 |
MEDIUM
Network
|
vmware
|
vsphere_client
|
VMware vSphere Client 5.5 before U3e and 6.0 before U2a allows remote vCenter Server and ESXi instances to read arbitrary files via an XML document containing an external entity declaration in conjun…
|
CWE-611
XXE
|
CVE-2016-7458
|
2024-11-21 11:58 |
2016-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|