|
265511
|
9.8 |
CRITICAL
Network
|
cisco
|
email_security_appliance_firmware
|
Cisco IronPort AsyncOS 9.1.2-023, 9.1.2-028, 9.1.2-036, 9.7.2-046, 9.7.2-047, 9.7.2-054, 10.0.0-124, and 10.0.0-125 on Email Security Appliance (ESA) devices, when Enrollment Client before 1.0.2-065 …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-6406
|
2024-11-21 11:56 |
2016-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265512
|
9.8 |
CRITICAL
Network
|
cisco
|
cloud_services_platform_2100
|
Cisco Cloud Services Platform (CSP) 2100 2.0 allows remote attackers to execute arbitrary code via a crafted dnslookup command in an HTTP request, aka Bug ID CSCuz89093.
|
CWE-20
Improper Input Validation
|
CVE-2016-6374
|
2024-11-21 11:56 |
2016-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265513
|
7.2 |
HIGH
Network
|
cisco
|
cloud_services_platform_2100
|
The web-based GUI in Cisco Cloud Services Platform (CSP) 2100 2.0 allows remote authenticated administrators to execute arbitrary OS commands as root via crafted platform commands, aka Bug ID CSCva00…
|
CWE-78
OS Command
|
CVE-2016-6373
|
2024-11-21 11:56 |
2016-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265514
|
6.5 |
MEDIUM
Network
|
huawei
|
ac6003_firmware ac6005_firmware ac6605_firmware acu2_firmware
|
Huawei AC6003, AC6005, AC6605, and ACU2 access controllers with software before V200R006C10SPC200 allows remote authenticated users to cause a denial of service (device restart) via crafted CAPWAP pa…
|
CWE-20
Improper Input Validation
|
CVE-2016-6824
|
2024-11-21 11:56 |
2016-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265515
|
7.5 |
HIGH
Network
|
huawei
|
usg2100_firmware usg2200_firmware usg5100_firmware usg5500_firmware
|
Buffer overflow in the Authentication, Authorization and Accounting (AAA) module in Huawei USG2100, USG2200, USG5100, and USG5500 unified security gateways with software before V300R001C10SPC600 allo…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-6669
|
2024-11-21 11:56 |
2016-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265516
|
9.8 |
CRITICAL
Network
|
debian artifex
|
debian_linux mupdf
|
Heap-based buffer overflow in the pdf_load_mesh_params function in pdf/pdf-shade.c in MuPDF allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a large decode a…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-6525
|
2024-11-21 11:56 |
2016-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265517
|
8.8 |
HIGH
Network
|
apache debian
|
jackrabbit debian_linux
|
Cross-site request forgery (CSRF) vulnerability in the CSRF content-type check in Jackrabbit-Webdav in Apache Jackrabbit 2.4.x before 2.4.6, 2.6.x before 2.6.6, 2.8.x before 2.8.3, 2.10.x before 2.10…
|
CWE-352
Origin Validation Error
|
CVE-2016-6801
|
2024-11-21 11:56 |
2016-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265518
|
9.8 |
CRITICAL
Network
|
dentsply_sirona
|
cdr_dicom
|
Dentsply Sirona (formerly Schick) CDR Dicom 5 and earlier has default passwords for the sa and cdr accounts, which allows remote attackers to obtain administrative access by leveraging knowledge of t…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2016-6530
|
2024-11-21 11:56 |
2016-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265519
|
7.5 |
HIGH
Network
|
apache
|
shiro
|
Apache Shiro before 1.3.2 allows attackers to bypass intended servlet filters and gain access by leveraging use of a non-root servlet context path.
|
CWE-284
Improper Access Control
|
CVE-2016-6802
|
2024-11-21 11:56 |
2016-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265520
|
9.8 |
CRITICAL
Network
|
oracle percona mariadb debian redhat
|
mysql percona_server mariadb debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux openstack enterprise_linux_server enterprise_linux_server_t…
|
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before 10.1.17; and Percona Server before 5.5.51-38.1, 5.6.x befo…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-6662
|
2024-11-21 11:56 |
2016-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|