|
270661
|
7.8 |
HIGH
Local
|
accellion
|
kiteworks_appliance
|
Accellion Kiteworks appliances before kw2016.03.00 use setuid-root permissions for /opt/bin/cli, which allows local users to gain privileges via unspecified vectors.
|
NVD-CWE-Other
|
CVE-2016-5662
|
2024-11-21 11:54 |
2016-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270662
|
8.8 |
HIGH
Network
|
redhat
|
cloudforms
|
The web UI in Red Hat CloudForms 4.1 allows remote authenticated users to execute arbitrary code via vectors involving "Lack of field filters."
|
CWE-284
Improper Access Control
|
CVE-2016-5383
|
2024-11-21 11:54 |
2016-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270663
|
7.5 |
HIGH
Network
|
ultravnc
|
repeater
|
UltraVNC Repeater before 1300 does not restrict destination IP addresses or TCP ports, which allows remote attackers to obtain open-proxy functionality by using a :: substring in between the IP addre…
|
CWE-284
Improper Access Control
|
CVE-2016-5673
|
2024-11-21 11:54 |
2016-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270664
|
9.8 |
CRITICAL
Network
|
dlink d-link
|
dir-868l_firmware dir-822_firmware dir-880l_firmware dir-850l_firmare dir-895l_firmware dir-817l\(w\)_firmware dir-818l\(w\)_firmware dir-890l_firmware dir-823_firmware dir…
|
Stack-based buffer overflow in dws/api/Login on D-Link DIR-850L B1 2.07 before 2.07WWB05, DIR-817 Ax, DIR-818LW Bx before 2.05b03beta03, DIR-822 C1 3.01 before 3.01WWb02, DIR-823 A1 1.00 before 1.00W…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-5681
|
2024-11-21 11:54 |
2016-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270665
|
7.5 |
HIGH
Network
|
zmodo
|
zp-ibh-13w zp-ne-14-s
|
ZModo ZP-NE14-S and ZP-IBH-13W devices do not enforce a WPA2 configuration setting, which allows remote attackers to trigger association with an arbitrary access point by using a recognized SSID valu…
|
CWE-284
Improper Access Control
|
CVE-2016-5650
|
2024-11-21 11:54 |
2016-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270666
|
7.3 |
HIGH
Network
|
rockwellautomation
|
1766-l32bxb 1766-l32bwaa 1766-l32awaa 1766-l32bwa 1766-l32awa 1766-l32bxba
|
Rockwell Automation MicroLogix 1400 PLC 1766-L32BWA, 1766-L32AWA, 1766-L32BXB, 1766-L32BWAA, 1766-L32AWAA, and 1766-L32BXBA devices have a hardcoded SNMP community, which makes it easier for remote a…
|
CWE-284
Improper Access Control
|
CVE-2016-5645
|
2024-11-21 11:54 |
2016-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270667
|
5.3 |
MEDIUM
Network
|
theforeman
|
foreman
|
Foreman before 1.11.4 and 1.12.x before 1.12.1 allow remote authenticated users with the view_hosts permission containing a filter to obtain sensitive network interface information via a request to A…
|
CWE-200
Information Exposure
|
CVE-2016-5390
|
2024-11-21 11:54 |
2016-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270668
|
7.5 |
HIGH
Network
|
f5
|
big-ip_application_acceleration_manager big-ip_webaccelerator big-ip_analytics big-ip_domain_name_system big-ip_edge_gateway big-ip_access_policy_manager big-ip_local_traffic_manage…
|
The default configuration of the IPsec IKE peer listener in F5 BIG-IP LTM, Analytics, APM, ASM, and Link Controller 11.2.1 before HF16, 11.4.x, 11.5.x before 11.5.4 HF2, 11.6.x before 11.6.1, and 12.…
|
CWE-284
Improper Access Control
|
CVE-2016-5736
|
2024-11-21 11:54 |
2016-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270669
|
7.8 |
HIGH
Local
|
fedoraproject fontconfig_project debian canonical
|
fedora fontconfig debian_linux ubuntu_linux
|
fontconfig before 2.12.1 does not validate offsets, which allows local users to trigger arbitrary free calls and consequently conduct double free attacks and execute arbitrary code via a crafted cach…
|
CWE-415
Double Free
|
CVE-2016-5384
|
2024-11-21 11:54 |
2016-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270670
|
8.1 |
HIGH
Network
|
opensuse haxx canonical debian fedoraproject
|
leap libcurl ubuntu_linux debian_linux fedora opensuse
|
Use-after-free vulnerability in libcurl before 7.50.1 allows attackers to control which connection is used or possibly have unspecified other impact via unknown vectors.
|
CWE-416
Use After Free
|
CVE-2016-5421
|
2024-11-21 11:54 |
2016-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|