|
266721
|
6.5 |
MEDIUM
Adjacent
|
cisco
|
aironet_access_point_software
|
The rate-limit feature in the 802.11 protocol implementation on Cisco Aironet 1800, 2800, and 3800 devices with software before 8.2.121.0 and 8.3.x before 8.3.102.0 allows remote attackers to cause a…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-6363
|
2024-11-21 11:55 |
2016-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266722
|
7.8 |
HIGH
Local
|
cisco
|
aironet_access_point_software
|
Cisco Aironet 1800, 2800, and 3800 devices with software before 8.2.110.0, 8.2.12x before 8.2.121.0, and 8.3.x before 8.3.102.0 allow local users to gain privileges via crafted CLI parameters, aka Bu…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-6362
|
2024-11-21 11:55 |
2016-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266723
|
6.5 |
MEDIUM
Adjacent
|
cisco
|
aironet_access_point_software
|
The Aggregated MAC Protocol Data Unit (AMPDU) implementation on Cisco Aironet 1800, 2800, and 3800 devices with software before 8.2.121.0 and 8.3.x before 8.3.102.0 allows remote attackers to cause a…
|
CWE-20
Improper Input Validation
|
CVE-2016-6361
|
2024-11-21 11:55 |
2016-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266724
|
6.1 |
MEDIUM
Network
|
cisco
|
transport_gateway_installation_software
|
Cross-site scripting (XSS) vulnerability in Cisco Transport Gateway Installation Software 4.1(4.0) on Smart Call Home Transport Gateway devices allows remote attackers to inject arbitrary web script …
|
CWE-79
Cross-site Scripting
|
CVE-2016-6359
|
2024-11-21 11:55 |
2016-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266725
|
9.8 |
CRITICAL
Network
|
navis
|
webaccess
|
SQL injection vulnerability in news pages in Cargotec Navis WebAccess before 2016-08-10 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2016-5817
|
2024-11-21 11:55 |
2016-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266726
|
5.4 |
MEDIUM
Network
|
theforeman
|
foreman
|
Cross-site scripting (XSS) vulnerability in app/assets/javascripts/host_edit_interfaces.js in Foreman before 1.12.2 allows remote authenticated users to inject arbitrary web script or HTML via the ne…
|
CWE-79
Cross-site Scripting
|
CVE-2016-6320
|
2024-11-21 11:55 |
2016-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266727
|
6.1 |
MEDIUM
Network
|
theforeman
|
foreman
|
Cross-site scripting (XSS) vulnerability in app/helpers/form_helper.rb in Foreman before 1.12.2, as used by Remote Execution and possibly other plugins, allows remote attackers to inject arbitrary we…
|
CWE-79
Cross-site Scripting
|
CVE-2016-6319
|
2024-11-21 11:55 |
2016-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266728
|
9.1 |
CRITICAL
Network
|
debian collectd fedoraproject
|
debian_linux collectd fedora
|
Heap-based buffer overflow in the parse_packet function in network.c in collectd before 5.4.3 and 5.x before 5.5.2 allows remote attackers to cause a denial of service (daemon crash) or possibly exec…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-6254
|
2024-11-21 11:55 |
2016-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266729
|
5.8 |
MEDIUM
Local
|
sap
|
sapcar_archive_tool
|
SAP SAPCAR allows local users to change the permissions of arbitrary files and consequently gain privileges via a hard link attack on files extracted from an archive, possibly related to SAP Security…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-5847
|
2024-11-21 11:55 |
2016-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266730
|
5.5 |
MEDIUM
Local
|
sap
|
sapcar
|
SAP SAPCAR does not check the return value of file operations when extracting files, which allows remote attackers to cause a denial of service (program crash) via an invalid file name in an archive …
|
NVD-CWE-Other
|
CVE-2016-5845
|
2024-11-21 11:55 |
2016-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|