|
266121
|
8.1 |
HIGH
Network
|
oracle imagemagick
|
solaris imagemagick
|
The WPG parser in ImageMagick before 6.9.4-4 and 7.x before 7.0.1-5, when a memory limit is set, allows remote attackers to have unspecified impact via vectors related to the SetImageExtent return-va…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-5688
|
2024-11-21 11:54 |
2016-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266122
|
9.8 |
CRITICAL
Network
|
imagemagick oracle
|
imagemagick solaris
|
The VerticalFilter function in the DDS coder in ImageMagick before 6.9.4-3 and 7.x before 7.0.1-4 allows remote attackers to have unspecified impact via a crafted DDS file, which triggers an out-of-b…
|
CWE-125
Out-of-bounds Read
|
CVE-2016-5687
|
2024-11-21 11:54 |
2016-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266123
|
7.1 |
HIGH
Network
|
debian postgresql
|
debian_linux postgresql
|
PostgreSQL before 9.1.23, 9.2.x before 9.2.18, 9.3.x before 9.3.14, 9.4.x before 9.4.9, and 9.5.x before 9.5.4 might allow remote authenticated users with the CREATEDB or CREATEROLE role to gain supe…
|
CWE-94
Code Injection
|
CVE-2016-5424
|
2024-11-21 11:54 |
2016-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266124
|
8.3 |
HIGH
Network
|
debian postgresql
|
debian_linux postgresql
|
PostgreSQL before 9.1.23, 9.2.x before 9.2.18, 9.3.x before 9.3.14, 9.4.x before 9.4.9, and 9.5.x before 9.5.4 allow remote authenticated users to cause a denial of service (NULL pointer dereference …
|
CWE-476
NULL Pointer Dereference
|
CVE-2016-5423
|
2024-11-21 11:54 |
2016-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266125
|
5.9 |
MEDIUM
Network
|
google
|
android
|
The GPS component in Android before 2016-12-05 allows man-in-the-middle attackers to cause a denial of service (GPS signal-acquisition delay) via an incorrect xtra.bin or xtra2.bin file on a spoofed …
|
CWE-284
Improper Access Control
|
CVE-2016-5341
|
2024-11-21 11:54 |
2016-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266126
|
8.8 |
HIGH
Network
|
dell
|
idrac7_firmware idrac8_firmware
|
Dell iDRAC7 and iDRAC8 devices with firmware before 2.40.40.40 allow authenticated users to gain Bash shell access through a string injection.
|
CWE-74
Injection
|
CVE-2016-5685
|
2024-11-21 11:54 |
2016-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266127
|
8.8 |
HIGH
Network
|
apache
|
hadoop
|
In Apache Hadoop 2.6.x before 2.6.5 and 2.7.x before 2.7.3, a remote user who can authenticate with the HDFS NameNode can possibly run arbitrary commands with the same privileges as the HDFS service.
|
CWE-284
Improper Access Control
|
CVE-2016-5393
|
2024-11-21 11:54 |
2016-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266128
|
6.5 |
MEDIUM
Network
|
microfocus
|
host_access_management_and_security_server reflection_zfe reflection_for_the_web reflection_security_gateway
|
Administrative Server in Micro Focus Host Access Management and Security Server (MSS) and Reflection for the Web (RWeb) and Reflection Security Gateway (RSG) and Reflection ZFE (ZFE) allows remote un…
|
CWE-22 CWE-200
Path Traversal Information Exposure
|
CVE-2016-5765
|
2024-11-21 11:54 |
2016-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266129
|
9.1 |
CRITICAL
Network
|
novell
|
open_enterprise_server_11 open_enterprise_server_2015
|
Vulnerability in Novell Open Enterprise Server (OES2015 SP1 before Scheduled Maintenance Update 10992, OES2015 before Scheduled Maintenance Update 10990, OES11 SP3 before Scheduled Maintenance Update…
|
CWE-254
7PK - Security Features
|
CVE-2016-5763
|
2024-11-21 11:54 |
2016-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266130
|
8.8 |
HIGH
Network
|
microfocus
|
rumba_ftp
|
Micro Focus Rumba FTP 4.X client buffer overflow makes it possible to corrupt the stack and allow arbitrary code execution. Fixed in: Rumba FTP 4.5 (HF 14668). This can only occur if a client connect…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-5764
|
2024-11-21 11:54 |
2016-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|