|
267181
|
9.6 |
CRITICAL
Network
|
pivotal_software cloudfoundry
|
cloud_foundry_elastic_runtime cloud_foundry_uaa cloud_foundry_ops_manager cloud_foundry cloud_foundry_uaa_bosh
|
Multiple cross-site request forgery (CSRF) vulnerabilities in Pivotal Cloud Foundry (PCF) before 242; UAA 2.x before 2.7.4.7, 3.x before 3.3.0.5, and 3.4.x before 3.4.4; UAA BOSH before 11.5 and 12.x…
|
CWE-352
Origin Validation Error
|
CVE-2016-6637
|
2024-11-21 11:56 |
2016-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267182
|
5.3 |
MEDIUM
Network
|
pivotal_software cloudfoundry
|
cloud_foundry_elastic_runtime cloud_foundry_uaa cloud_foundry_ops_manager cloud_foundry cloud_foundry_uaa_bosh
|
The OAuth authorization implementation in Pivotal Cloud Foundry (PCF) before 242; UAA 2.x before 2.7.4.7, 3.x before 3.3.0.5, and 3.4.x before 3.4.4; UAA BOSH before 11.5 and 12.x before 12.5; Elasti…
|
CWE-601
Open Redirect
|
CVE-2016-6636
|
2024-11-21 11:56 |
2016-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267183
|
6.5 |
MEDIUM
Network
|
huawei
|
fusioncompute
|
Huawei FusionCompute before V100R005C10CP7002 stores cleartext AES keys in a file, which allows remote authenticated users to obtain sensitive information via unspecified vectors.
|
CWE-200
Information Exposure
|
CVE-2016-6827
|
2024-11-21 11:56 |
2016-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267184
|
6.5 |
MEDIUM
Network
|
huawei
|
anyoffice_secureapp
|
Huawei AnyMail before 2.6.0301.0060 allows remote attackers to cause a denial of service (application crash) via a crafted compressed email attachment.
|
CWE-284
Improper Access Control
|
CVE-2016-6826
|
2024-11-21 11:56 |
2016-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267185
|
7.5 |
HIGH
Network
|
huawei
|
s5300_firmware s12700_firmware s6300_firmware s7700_firmware s5700_firmware s6700_firmware s9700_firmware s9300_firmware
|
Memory leak in Huawei S9300, S5300, S5700, S6700, S7700, S9700, and S12700 devices allows remote attackers to cause a denial of service (memory consumption and restart) via a large number of malforme…
|
CWE-399
Resource Management Errors
|
CVE-2016-6518
|
2024-11-21 11:56 |
2016-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267186
|
6.1 |
MEDIUM
Network
|
huawei
|
oceanstor_ism
|
Cross-site scripting (XSS) vulnerability in the management interface in Huawei OceanStor ISM before V200R001C04SPC200 allows remote attackers to inject arbitrary web script or HTML via the loginName …
|
CWE-79
Cross-site Scripting
|
CVE-2016-6840
|
2024-11-21 11:56 |
2016-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267187
|
9.8 |
CRITICAL
Network
|
dexis
|
imaging_suite
|
DEXIS Imaging Suite 10 has a hardcoded password for the sa account, which allows remote attackers to obtain administrative access by entering this password in a DEXIS_DATA SQL Server session.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2016-6532
|
2024-11-21 11:56 |
2016-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267188
|
9.8 |
CRITICAL
Network
|
opendental
|
opendental
|
Open Dental 16.1 and earlier has a hardcoded MySQL root password, which allows remote attackers to obtain administrative access by leveraging access to intranet TCP port 3306. NOTE: the vendor dispu…
|
CWE-255
Credentials Management
|
CVE-2016-6531
|
2024-11-21 11:56 |
2016-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267189
|
7.8 |
HIGH
Local
|
cisco
|
application_policy_infrastructure_controller
|
The installation procedure on Cisco Application Policy Infrastructure Controller (APIC) devices 1.3(2f) mishandles binary files, which allows local users to obtain root access via unspecified vectors…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-6413
|
2024-11-21 11:56 |
2016-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267190
|
6.5 |
MEDIUM
Network
|
cisco
|
ios
|
The Cisco Application-hosting Framework (CAF) component in Cisco IOS 15.6(1)T1 and IOS XE, when the IOx feature set is enabled, allows man-in-the-middle attackers to trigger arbitrary downloads via c…
|
CWE-20
Improper Input Validation
|
CVE-2016-6412
|
2024-11-21 11:56 |
2016-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|