|
264731
|
8.1 |
HIGH
Network
|
netapp
|
vasa_provider
|
Versions of VASA Provider for Clustered Data ONTAP prior to 7.0P1 contain a web server that accepts plain text authentication. This could allow an unauthenticated attacker to obtain authentication cr…
|
CWE-255
Credentials Management
|
CVE-2016-6904
|
2024-11-21 11:57 |
2017-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264732
|
7.5 |
HIGH
Network
|
freeipa
|
freeipa
|
FreeIPA uses a default password policy that locks an account after 5 unsuccessful authentication attempts, which allows remote attackers to cause a denial of service by locking out the account in whi…
|
CWE-255
Credentials Management
|
CVE-2016-7030
|
2024-11-21 11:57 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264733
|
7.8 |
HIGH
Local
|
redhat
|
storage_console storage_console_node
|
rhscon-ceph in Red Hat Storage Console 2 x86_64 and Red Hat Storage Console Node 2 x86_64 allows local users to obtain the password as cleartext.
|
CWE-255
Credentials Management
|
CVE-2016-7062
|
2024-11-21 11:57 |
2017-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264734
|
9.8 |
CRITICAL
Network
|
redhat
|
enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_hpc_node
|
SerializableProvider in RESTEasy in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Workstation 7 allows remot…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2016-7050
|
2024-11-21 11:57 |
2017-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264735
|
5.3 |
MEDIUM
Network
|
citrix
|
xenmobile_server
|
Citrix XenMobile Server before 10.5.0.24 allows man-in-the-middle attackers to trigger HTTP 302 redirections via vectors involving the HTTP Host header and a cached page. NOTE: the vendor reports "o…
|
CWE-20
Improper Input Validation
|
CVE-2016-6877
|
2024-11-21 11:57 |
2017-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264736
|
7.5 |
HIGH
Network
|
openssl
|
openssl
|
In OpenSSL 1.1.0 before 1.1.0c, TLS connections using *-CHACHA20-POLY1305 ciphersuites are susceptible to a DoS attack by corrupting larger payloads. This can result in an OpenSSL crash. This issue i…
|
CWE-284
Improper Access Control
|
CVE-2016-7054
|
2024-11-21 11:57 |
2017-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264737
|
7.5 |
HIGH
Network
|
openssl
|
openssl
|
In OpenSSL 1.1.0 before 1.1.0c, applications parsing invalid CMS structures can crash with a NULL pointer dereference. This is caused by a bug in the handling of the ASN.1 CHOICE type in OpenSSL 1.1.…
|
CWE-476
NULL Pointer Dereference
|
CVE-2016-7053
|
2024-11-21 11:57 |
2017-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264738
|
5.9 |
MEDIUM
Network
|
openssl nodejs
|
openssl node.js
|
There is a carry propagating bug in the Broadwell-specific Montgomery multiplication procedure in OpenSSL 1.0.2 and 1.1.0 before 1.1.0c that handles input lengths divisible by, but longer than 256 bi…
|
NVD-CWE-noinfo
|
CVE-2016-7055
|
2024-11-21 11:57 |
2017-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264739
|
7.8 |
HIGH
Local
|
nvidia
|
shield_tablet_firmware shield_tablet_tk1_firmware shield_tv_firmware video_driver
|
Stack-based buffer overflow in nvhost_job.c in the NVIDIA video driver for Android, Shield TV before OTA 3.3, Shield Table before OTA 4.4, and Shield Table TK1 before OTA 1.5.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-6915
|
2024-11-21 11:57 |
2017-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264740
|
7.8 |
HIGH
Local
|
nvidia
|
shield_tablet_firmware shield_tablet_tk1_firmware shield_tv_firmware video_driver
|
Buffer overflow in nvhost_job.c in the NVIDIA video driver for Android, Shield TV before OTA 3.3, Shield Table before OTA 4.4, and Shield Table TK1 before OTA 1.5.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-6917
|
2024-11-21 11:57 |
2017-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|