|
268481
|
6.1 |
MEDIUM
Network
|
rubyonrails debian
|
ruby_on_rails rails debian_linux
|
Cross-site scripting (XSS) vulnerability in Action View in Ruby on Rails 3.x before 3.2.22.3, 4.x before 4.2.7.1, and 5.x before 5.0.0.1 might allow remote attackers to inject arbitrary web script or…
|
CWE-79
Cross-site Scripting
|
CVE-2016-6316
|
2024-11-21 11:55 |
2016-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268482
|
7.0 |
HIGH
Local
|
huawei
|
honor_4c_firmware
|
The Camera driver in Huawei Honor 4C smartphones with software CHM-UL00C00 before CHM-UL00C00B564, CHM-TL00C01 before CHM-TL00C01B564, and CHM-TL00C00 before CHM-TL00HC00B564 allows attackers to caus…
|
CWE-284
Improper Access Control
|
CVE-2016-6184
|
2024-11-21 11:55 |
2016-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268483
|
7.0 |
HIGH
Local
|
huawei
|
honor_4c_firmware
|
The Camera driver in Huawei Honor 4C smartphones with software CHM-UL00C00 before CHM-UL00C00B564, CHM-TL00C01 before CHM-TL00C01B564, and CHM-TL00C00 before CHM-TL00HC00B564 allows attackers to caus…
|
CWE-284
Improper Access Control
|
CVE-2016-6183
|
2024-11-21 11:55 |
2016-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268484
|
7.0 |
HIGH
Local
|
huawei
|
honor_4c_firmware
|
The Camera driver in Huawei Honor 4C smartphones with software CHM-UL00C00 before CHM-UL00C00B564, CHM-TL00C01 before CHM-TL00C01B564, and CHM-TL00C00 before CHM-TL00HC00B564 allows attackers to caus…
|
CWE-284
Improper Access Control
|
CVE-2016-6182
|
2024-11-21 11:55 |
2016-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268485
|
7.0 |
HIGH
Local
|
huawei
|
honor_4c_firmware
|
The Camera driver in Huawei Honor 4C smartphones with software CHM-UL00C00 before CHM-UL00C00B564, CHM-TL00C01 before CHM-TL00C01B564, and CHM-TL00C00 before CHM-TL00HC00B564 allows attackers to caus…
|
CWE-284
Improper Access Control
|
CVE-2016-6181
|
2024-11-21 11:55 |
2016-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268486
|
7.0 |
HIGH
Local
|
huawei
|
honor_4c_firmware
|
The Camera driver in Huawei Honor 4C smartphones with software CHM-UL00C00 before CHM-UL00C00B564, CHM-TL00C01 before CHM-TL00C01B564, and CHM-TL00C00 before CHM-TL00HC00B564 allows attackers to caus…
|
CWE-284
Improper Access Control
|
CVE-2016-6180
|
2024-11-21 11:55 |
2016-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268487
|
6.7 |
MEDIUM
Local
|
qemu canonical debian
|
qemu ubuntu_linux debian_linux
|
The esp_do_dma function in hw/scsi/esp.c in QEMU (aka Quick Emulator), when built with ESP/NCR53C9x controller emulation support, allows local guest OS administrators to cause a denial of service (ou…
|
NVD-CWE-noinfo
|
CVE-2016-6351
|
2024-11-21 11:55 |
2016-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268488
|
7.5 |
HIGH
Network
|
redhat
|
resteasy
|
RESTEasy enables GZIPInterceptor, which allows remote attackers to cause a denial of service via unspecified vectors.
|
NVD-CWE-noinfo
|
CVE-2016-6346
|
2024-11-21 11:55 |
2016-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268489
|
6.5 |
MEDIUM
Network
|
redhat
|
resteasy
|
RESTEasy allows remote authenticated users to obtain sensitive information by leveraging "insufficient use of random values" in async jobs.
|
CWE-200
Information Exposure
|
CVE-2016-6345
|
2024-11-21 11:55 |
2016-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268490
|
5.3 |
MEDIUM
Network
|
redhat
|
jboss_bpm_suite
|
Red Hat JBoss BPM Suite 6.3.x does not include the HTTPOnly flag in a Set-Cookie header for session cookies, which makes it easier for remote attackers to obtain potentially sensitive information via…
|
CWE-200
Information Exposure
|
CVE-2016-6344
|
2024-11-21 11:55 |
2016-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|