|
265111
|
7.5 |
HIGH
Network
|
huawei
|
rh5885_v3_server_firmware rh1288_v3_server_firmware rh2288_v3_server_firmware rh2288h_v3_server_firmware xh620_v3_server_firmware xh622_v3_server_firmware xh628_v3_server_firmware
|
The Intelligent Baseboard Management Controller (iBMC) in Huawei RH1288 V3 servers with software before V100R003C00SPC613, RH2288 V3 servers with software before V100R003C00SPC617, RH2288H V3 servers…
|
CWE-310 CWE-200
Cryptographic Issues Information Exposure
|
CVE-2016-6899
|
2024-11-21 11:57 |
2016-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265112
|
7.5 |
HIGH
Network
|
f5
|
big-ip_local_traffic_manager big-ip_webaccelerator big-ip_application_acceleration_manager big-ip_global_traffic_manager big-ip_link_controller big-ip_advanced_firewall_manager big-…
|
The RESOLV::lookup iRule command in F5 BIG-IP LTM, APM, ASM, and Link Controller 10.2.1 through 10.2.4, 11.2.1, 11.4.x, 11.5.x before 11.5.4 HF2, 11.6.x before 11.6.1, and 12.0.0 before HF3; BIG-IP A…
|
CWE-399
Resource Management Errors
|
CVE-2016-6876
|
2024-11-21 11:57 |
2016-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265113
|
8.8 |
HIGH
Network
|
redhat
|
jboss_bpm_suite
|
The dashbuilder in Red Hat JBoss BPM Suite 6.3.2 does not properly handle CSRF tokens generated during an active session and includes them in query strings, which makes easier for remote attackers to…
|
CWE-352
Origin Validation Error
|
CVE-2016-7034
|
2024-11-21 11:57 |
2016-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265114
|
6.1 |
MEDIUM
Network
|
redhat
|
jboss_bpm_suite
|
Multiple cross-site scripting (XSS) vulnerabilities in the admin pages in dashbuilder in Red Hat JBoss BPM Suite 6.3.2 allow remote attackers to inject arbitrary web script or HTML via unspecified ve…
|
CWE-79
Cross-site Scripting
|
CVE-2016-7033
|
2024-11-21 11:57 |
2016-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265115
|
5.3 |
MEDIUM
Network
|
microsoft google apple opera mozilla
|
edge internet_explorer chrome safari opera_browser firefox
|
The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by lever…
|
CWE-200
Information Exposure
|
CVE-2016-7153
|
2024-11-21 11:57 |
2016-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265116
|
5.3 |
MEDIUM
Network
|
opera apple mozilla microsoft google
|
opera safari firefox edge internet_explorer chrome
|
The HTTPS protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by levera…
|
CWE-200
Information Exposure
|
CVE-2016-7152
|
2024-11-21 11:57 |
2016-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265117
|
8.8 |
HIGH
Network
|
siemens
|
en100_ethernet_module_firmware
|
A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01; Firmware variant Modbus TCP for EN100 Ethernet module : All versions < V1.11.0…
|
CWE-287
Improper Authentication
|
CVE-2016-7114
|
2024-11-21 11:57 |
2016-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265118
|
7.5 |
HIGH
Network
|
siemens
|
en100_ethernet_module_firmware
|
A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01; Firmware variant Modbus TCP for EN100 Ethernet module : All versions < V1.11.0…
|
CWE-399
Resource Management Errors
|
CVE-2016-7113
|
2024-11-21 11:57 |
2016-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265119
|
9.8 |
CRITICAL
Network
|
siemens
|
en100_ethernet_module_firmware
|
A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01; Firmware variant Modbus TCP for EN100 Ethernet module : All versions < V1.11.0…
|
CWE-287
Improper Authentication
|
CVE-2016-7112
|
2024-11-21 11:57 |
2016-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265120
|
8.8 |
HIGH
Network
|
gnu
|
mailman
|
Cross-site request forgery (CSRF) vulnerability in the admin web interface in GNU Mailman before 2.1.15 allows remote attackers to hijack the authentication of administrators.
|
CWE-352
Origin Validation Error
|
CVE-2016-7123
|
2024-11-21 11:57 |
2016-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|