|
270671
|
7.5 |
HIGH
Network
|
debian haxx opensuse
|
debian_linux libcurl leap
|
curl and libcurl before 7.50.1 do not check the client certificate when choosing the TLS connection to reuse, which might allow remote attackers to hijack the authentication of the connection by leve…
|
CWE-285
Improper Authorization
|
CVE-2016-5420
|
2024-11-21 11:54 |
2016-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270672
|
7.5 |
HIGH
Network
|
haxx debian opensuse
|
libcurl debian_linux leap
|
curl and libcurl before 7.50.1 do not prevent TLS session resumption when the client certificate has changed, which allows remote attackers to bypass intended restrictions by resuming a session.
|
CWE-310
Cryptographic Issues
|
CVE-2016-5419
|
2024-11-21 11:54 |
2016-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270673
|
9.8 |
CRITICAL
Network
|
oracle redhat
|
linux enterprise_linux_server enterprise_linux_workstation
|
Stack-based buffer overflow in the munge_other_line function in cachemgr.cgi in the squid package before 3.1.23-16.el6_8.6 in Red Hat Enterprise Linux 6 allows remote attackers to execute arbitrary c…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-5408
|
2024-11-21 11:54 |
2016-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270674
|
6.1 |
MEDIUM
Network
|
vmware
|
esxi vcenter_server
|
CRLF injection vulnerability in VMware vCenter Server 6.0 before U2 and ESXi 6.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified v…
|
CWE-93
CRLF Injection
|
CVE-2016-5331
|
2024-11-21 11:54 |
2016-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270675
|
7.8 |
HIGH
Local
|
vmware
|
workstation_player workstation_pro esxi fusion tools
|
Untrusted search path vulnerability in the HGFS (aka Shared Folders) feature in VMware Tools 10.0.5 in VMware ESXi 5.0 through 6.0, VMware Workstation Pro 12.1.x before 12.1.1, VMware Workstation Pla…
|
CWE-426
Untrusted Search Path
|
CVE-2016-5330
|
2024-11-21 11:54 |
2016-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270676
|
7.8 |
HIGH
Local
|
google linux
|
android linux_kernel
|
The is_ashmem_file function in drivers/staging/android/ashmem.c in a certain Qualcomm Innovation Center (QuIC) Android patch for the Linux kernel 3.x mishandles pointer validation within the KGSL Lin…
|
CWE-20
Improper Input Validation
|
CVE-2016-5340
|
2024-11-21 11:54 |
2016-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270677
|
5.9 |
MEDIUM
Network
|
wireshark
|
wireshark
|
epan/dissectors/packet-wbxml.c in the WBXML dissector in Wireshark 1.12.x before 1.12.12 mishandles offsets, which allows remote attackers to cause a denial of service (integer overflow and infinite …
|
CWE-119 CWE-399
Incorrect Access of Indexable Resource ('Range Error') Resource Management Errors
|
CVE-2016-5359
|
2024-11-21 11:54 |
2016-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270678
|
5.9 |
MEDIUM
Network
|
wireshark oracle
|
wireshark solaris
|
epan/dissectors/packet-pktap.c in the Ethernet dissector in Wireshark 2.x before 2.0.4 mishandles the packet-header data type, which allows remote attackers to cause a denial of service (application …
|
CWE-20
Improper Input Validation
|
CVE-2016-5358
|
2024-11-21 11:54 |
2016-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270679
|
5.9 |
MEDIUM
Network
|
wireshark oracle
|
wireshark solaris
|
wiretap/netscreen.c in the NetScreen file parser in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles sscanf unsigned-integer processing, which allows remote attackers to cause a denial…
|
CWE-20
Improper Input Validation
|
CVE-2016-5357
|
2024-11-21 11:54 |
2016-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270680
|
5.9 |
MEDIUM
Network
|
wireshark
|
wireshark
|
wiretap/cosine.c in the CoSine file parser in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles sscanf unsigned-integer processing, which allows remote attackers to cause a denial of se…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-5356
|
2024-11-21 11:54 |
2016-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|