|
264701
|
7.5 |
HIGH
Network
|
gnu
|
gnutls
|
The gnutls_ocsp_resp_check_crt function in lib/x509/ocsp.c in GnuTLS before 3.4.15 and 3.5.x before 3.5.4 does not verify the serial length of an OCSP response, which might allow remote attackers to …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-7444
|
2024-11-21 11:58 |
2016-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264702
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Google Chrome before 53.0.2785.113 does not ensure that the recipient of a certain IPC message is a valid RenderFrame or RenderWidget, which allows remote attackers to cause a denial of service (inva…
|
NVD-CWE-noinfo
|
CVE-2016-7549
|
2024-11-21 11:58 |
2016-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264703
|
7.5 |
HIGH
Network
|
pritunl
|
pritunl-client
|
A flaw was found in pritunl-client before version 1.0.1116.6. A lack of signature verification leads to sensitive information leakage
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2016-7064
|
2024-11-21 11:57 |
2020-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264704
|
9.8 |
CRITICAL
Network
|
pritunl
|
pritunl-client
|
A flaw was found in pritunl-client before version 1.0.1116.6. Arbitrary write to user specified path may lead to privilege escalation.
|
CWE-22
Path Traversal
|
CVE-2016-7063
|
2024-11-21 11:57 |
2020-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264705
|
9.8 |
CRITICAL
Network
|
lexmark
|
markvision_enterprise
|
Lexmark Markvision Enterprise (MVE) before 2.4.1 allows remote attackers to execute arbitrary commands by uploading files. (
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2016-6918
|
2024-11-21 11:57 |
2020-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264706
|
9.8 |
CRITICAL
Network
|
php
|
ext-http
|
A type confusion vulnerability in the merge_param() function of php_http_params.c in PHP's pecl-http extension 3.1.0beta2 (PHP 7) and earlier as well as 2.6.0beta2 (PHP 5) and earlier allows attacker…
|
CWE-704
Incorrect Type Conversion or Cast
|
CVE-2016-7398
|
2024-11-21 11:57 |
2019-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264707
|
9.8 |
CRITICAL
Network
|
openstack
|
magnum
|
OpenStack Magnum passes OpenStack credentials into the Heat templates creating its instances. While these should just be used for retrieving the instances' SSL certificates, they allow full API acces…
|
CWE-200
Information Exposure
|
CVE-2016-7404
|
2024-11-21 11:57 |
2019-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264708
|
9.8 |
CRITICAL
Network
|
redhat
|
kie-server
|
It has been reported that KIE server and Busitess Central before version 7.21.0.Final contain username and password as plaintext Java properties. Any app deployed on the same server would have access…
|
-
|
CVE-2016-7043
|
2024-11-21 11:57 |
2019-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264709
|
5.5 |
MEDIUM
Local
|
capstone-engine
|
capstone
|
Capstone 3.0.4 has an out-of-bounds vulnerability (SEGV caused by a read memory access) in X86_insn_reg_intel in arch/X86/X86Mapping.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2016-7151
|
2024-11-21 11:57 |
2019-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264710
|
7.8 |
HIGH
Local
|
redhat
|
jboss_enterprise_application_platform
|
It was found that the improper default permissions on /tmp/auth directory in JBoss Enterprise Application Platform before 7.1.0 can allow any local user to connect to CLI and allow the user to execut…
|
CWE-275
Permission Issues
|
CVE-2016-7066
|
2024-11-21 11:57 |
2018-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|