|
266241
|
7.5 |
HIGH
Adjacent
|
huawei
|
ws331a_router_firmware
|
The management interface of Huawei WS331a routers with software before WS331a-10 V100R001C01B112 allows remote attackers to bypass authentication and obtain administrative access by sending "special …
|
CWE-287
Improper Authentication
|
CVE-2016-6159
|
2024-11-21 11:55 |
2016-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266242
|
6.1 |
MEDIUM
Network
|
huawei
|
ws331a_router_firmware
|
Multiple cross-site request forgery (CSRF) vulnerabilities in Huawei WS331a routers with software before WS331a-10 V100R001C01B112 allow remote attackers to hijack the authentication of administrator…
|
CWE-352
Origin Validation Error
|
CVE-2016-6158
|
2024-11-21 11:55 |
2016-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266243
|
6.5 |
MEDIUM
Network
|
libarchive redhat oracle
|
libarchive enterprise_linux_hpc_node enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation enterprise_linux_server_aus enterprise_linux_server_eus enterpr…
|
Integer overflow in the ISO parser in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) via a crafted ISO file.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2016-5844
|
2024-11-21 11:55 |
2016-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266244
|
8.6 |
HIGH
Local
|
rockwellautomation
|
rslogix_500_starter_edition rslogix_micro_starter_lite rslogix_micro_developer rslogix_500_standard_edition rslogix_500_professional_edition
|
Buffer overflow in Rockwell Automation RSLogix Micro Starter Lite, RSLogix Micro Developer, RSLogix 500 Starter Edition, RSLogix 500 Standard Edition, and RSLogix 500 Professional Edition allows remo…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-5814
|
2024-11-21 11:55 |
2016-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266245
|
9.4 |
CRITICAL
Network
|
otrs
|
faq
|
Multiple SQL injection vulnerabilities in the FAQ package 2.x before 2.3.6, 4.x before 4.0.5, and 5.x before 5.0.5 in Open Ticket Request System (OTRS) allow remote attackers to execute arbitrary SQL…
|
CWE-89
SQL Injection
|
CVE-2016-5843
|
2024-11-21 11:55 |
2016-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266246
|
9.8 |
CRITICAL
Network
|
nodejs openssl
|
node.js openssl
|
Integer overflow in the MDC2_Update function in crypto/mdc2/mdc2dgst.c in OpenSSL before 1.1.0 allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or poss…
|
CWE-787
Out-of-bounds Write
|
CVE-2016-6303
|
2024-11-21 11:55 |
2016-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266247
|
7.5 |
HIGH
Network
|
openssl oracle
|
openssl solaris linux
|
The tls_decrypt_ticket function in ssl/t1_lib.c in OpenSSL before 1.1.0 does not consider the HMAC size during validation of the ticket length, which allows remote attackers to cause a denial of serv…
|
CWE-20
Improper Input Validation
|
CVE-2016-6302
|
2024-11-21 11:55 |
2016-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266248
|
4.3 |
MEDIUM
Network
|
cisco
|
hosted_collaboration_mediation_fulfillment
|
Directory traversal vulnerability in the web interface in Cisco Hosted Collaboration Mediation Fulfillment (HCM-F) 10.6(3) and earlier allows remote authenticated users to read arbitrary files via a …
|
CWE-22
Path Traversal
|
CVE-2016-6370
|
2024-11-21 11:55 |
2016-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266249
|
6.5 |
MEDIUM
Network
|
ibm
|
websphere_portal
|
IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF30, 8.0.0 through 8.0.0.1 CF21, and 8.5.0 before CF12 allows remote authenticated users to cause a…
|
CWE-284
Improper Access Control
|
CVE-2016-5954
|
2024-11-21 11:55 |
2016-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266250
|
5.5 |
MEDIUM
Local
|
ibm
|
tivoli_storage_manager_for_space_management
|
IBM Tivoli Storage Manager for Space Management (aka Spectrum Protect for Space Management) 6.3.x before 6.3.2.6, 6.4.x before 6.4.3.3, and 7.1.x before 7.1.6, when certain dsmsetpw tracing is config…
|
CWE-200
Information Exposure
|
CVE-2016-5927
|
2024-11-21 11:55 |
2016-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|