|
267191
|
7.5 |
HIGH
Network
|
cisco
|
firesight_system_software
|
Cisco Firepower Management Center and FireSIGHT System Software 6.0.1 mishandle comparisons between URLs and X.509 certificates, which allows remote attackers to bypass intended do-not-decrypt settin…
|
CWE-20
Improper Input Validation
|
CVE-2016-6411
|
2024-11-21 11:56 |
2016-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267192
|
6.5 |
MEDIUM
Network
|
cisco
|
ios
|
The Cisco Application-hosting Framework (CAF) component in Cisco IOS 15.6(1)T1 and IOS XE, when the IOx feature set is enabled, allows remote authenticated users to read arbitrary files via unspecifi…
|
CWE-20
Improper Input Validation
|
CVE-2016-6410
|
2024-11-21 11:56 |
2016-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267193
|
7.5 |
HIGH
Network
|
cisco
|
ios
|
The Data in Motion (DMo) component in Cisco IOS 15.6(1)T and IOS XE, when the IOx feature set is enabled, allows remote attackers to cause a denial of service (out-of-bounds access) via crafted traff…
|
CWE-399
Resource Management Errors
|
CVE-2016-6409
|
2024-11-21 11:56 |
2016-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267194
|
7.5 |
HIGH
Network
|
cisco
|
prime_home
|
Cisco Prime Home 5.2.0 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML Externa…
|
CWE-611
XXE
|
CVE-2016-6408
|
2024-11-21 11:56 |
2016-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267195
|
7.8 |
HIGH
Local
|
cisco
|
ios
|
iox in Cisco IOS, possibly 15.6 and earlier, and IOS XE, possibly 3.18 and earlier, allows local users to execute arbitrary IOx Linux commands on the guest OS via crafted iox command-line options, ak…
|
CWE-78
OS Command
|
CVE-2016-6414
|
2024-11-21 11:56 |
2016-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267196
|
9.8 |
CRITICAL
Network
|
cisco
|
email_security_appliance_firmware
|
Cisco IronPort AsyncOS 9.1.2-023, 9.1.2-028, 9.1.2-036, 9.7.2-046, 9.7.2-047, 9.7.2-054, 10.0.0-124, and 10.0.0-125 on Email Security Appliance (ESA) devices, when Enrollment Client before 1.0.2-065 …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-6406
|
2024-11-21 11:56 |
2016-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267197
|
9.8 |
CRITICAL
Network
|
cisco
|
cloud_services_platform_2100
|
Cisco Cloud Services Platform (CSP) 2100 2.0 allows remote attackers to execute arbitrary code via a crafted dnslookup command in an HTTP request, aka Bug ID CSCuz89093.
|
CWE-20
Improper Input Validation
|
CVE-2016-6374
|
2024-11-21 11:56 |
2016-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267198
|
7.2 |
HIGH
Network
|
cisco
|
cloud_services_platform_2100
|
The web-based GUI in Cisco Cloud Services Platform (CSP) 2100 2.0 allows remote authenticated administrators to execute arbitrary OS commands as root via crafted platform commands, aka Bug ID CSCva00…
|
CWE-78
OS Command
|
CVE-2016-6373
|
2024-11-21 11:56 |
2016-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267199
|
6.5 |
MEDIUM
Network
|
huawei
|
ac6003_firmware ac6005_firmware ac6605_firmware acu2_firmware
|
Huawei AC6003, AC6005, AC6605, and ACU2 access controllers with software before V200R006C10SPC200 allows remote authenticated users to cause a denial of service (device restart) via crafted CAPWAP pa…
|
CWE-20
Improper Input Validation
|
CVE-2016-6824
|
2024-11-21 11:56 |
2016-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267200
|
7.5 |
HIGH
Network
|
huawei
|
usg2100_firmware usg2200_firmware usg5100_firmware usg5500_firmware
|
Buffer overflow in the Authentication, Authorization and Accounting (AAA) module in Huawei USG2100, USG2200, USG5100, and USG5500 unified security gateways with software before V300R001C10SPC600 allo…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-6669
|
2024-11-21 11:56 |
2016-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|