|
267201
|
9.8 |
CRITICAL
Network
|
debian artifex
|
debian_linux mupdf
|
Heap-based buffer overflow in the pdf_load_mesh_params function in pdf/pdf-shade.c in MuPDF allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a large decode a…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-6525
|
2024-11-21 11:56 |
2016-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267202
|
8.8 |
HIGH
Network
|
apache debian
|
jackrabbit debian_linux
|
Cross-site request forgery (CSRF) vulnerability in the CSRF content-type check in Jackrabbit-Webdav in Apache Jackrabbit 2.4.x before 2.4.6, 2.6.x before 2.6.6, 2.8.x before 2.8.3, 2.10.x before 2.10…
|
CWE-352
Origin Validation Error
|
CVE-2016-6801
|
2024-11-21 11:56 |
2016-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267203
|
9.8 |
CRITICAL
Network
|
dentsply_sirona
|
cdr_dicom
|
Dentsply Sirona (formerly Schick) CDR Dicom 5 and earlier has default passwords for the sa and cdr accounts, which allows remote attackers to obtain administrative access by leveraging knowledge of t…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2016-6530
|
2024-11-21 11:56 |
2016-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267204
|
7.5 |
HIGH
Network
|
apache
|
shiro
|
Apache Shiro before 1.3.2 allows attackers to bypass intended servlet filters and gain access by leveraging use of a non-root servlet context path.
|
CWE-284
Improper Access Control
|
CVE-2016-6802
|
2024-11-21 11:56 |
2016-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267205
|
9.8 |
CRITICAL
Network
|
oracle percona mariadb debian redhat
|
mysql percona_server mariadb debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux openstack enterprise_linux_server enterprise_linux_server_t…
|
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before 10.1.17; and Percona Server before 5.5.51-38.1, 5.6.x befo…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-6662
|
2024-11-21 11:56 |
2016-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267206
|
7.5 |
HIGH
Network
|
aver
|
eh6108h\+_firmware
|
AVer Information EH6108H+ devices with firmware X9.03.24.00.07l store passwords in a cleartext base64 format and require cleartext credentials in HTTP Cookie headers, which allows context-dependent a…
|
CWE-200
Information Exposure
|
CVE-2016-6537
|
2024-11-21 11:56 |
2016-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267207
|
9.8 |
CRITICAL
Network
|
aver
|
eh6108h\+_firmware
|
The /setup URI on AVer Information EH6108H+ devices with firmware X9.03.24.00.07l allows remote attackers to bypass intended page-access restrictions or modify passwords by leveraging knowledge of a …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-6536
|
2024-11-21 11:56 |
2016-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267208
|
9.8 |
CRITICAL
Network
|
aver
|
eh6108h\+_firmware
|
AVer Information EH6108H+ devices with firmware X9.03.24.00.07l have hardcoded accounts, which allows remote attackers to obtain root access by leveraging knowledge of the credentials and establishin…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2016-6535
|
2024-11-21 11:56 |
2016-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267209
|
6.5 |
MEDIUM
Network
|
cisco
|
fog_director
|
Cisco Fog Director 1.0(0) for IOx allows remote authenticated users to bypass intended access restrictions and write to arbitrary files via the Cartridge interface, aka Bug ID CSCuz89368.
|
CWE-20
Improper Input Validation
|
CVE-2016-6405
|
2024-11-21 11:56 |
2016-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267210
|
6.1 |
MEDIUM
Network
|
cisco
|
ios
|
Cross-site scripting (XSS) vulnerability in the web framework in Cisco IOx Local Manager in IOS 15.5(2)T and IOS XE allows remote attackers to inject arbitrary web script or HTML via a crafted URL, a…
|
CWE-79
Cross-site Scripting
|
CVE-2016-6404
|
2024-11-21 11:56 |
2016-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|