CVE List

Id CVE No. Status Description Phase Votes Comments Actions
93421  CVE-2016-6601  Candidate  Directory traversal vulnerability in the file download functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to read arbitrary files via a .. (dot dot) in the fileName parameter to servlets/FetchFile.  Assigned (20160804)  None (candidate not yet proposed)    View
93422  CVE-2016-6602  Candidate  ZOHO WebNMS Framework 5.2 and 5.2 SP1 use a weak obfuscation algorithm to store passwords, which allows context-dependent attackers to obtain cleartext passwords by leveraging access to WEB-INF/conf/securitydbData.xml. NOTE: this issue can be combined with CVE-2016-6601 for a remote exploit.  Assigned (20160804)  None (candidate not yet proposed)    View
93423  CVE-2016-6603  Candidate  ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to bypass authentication and impersonate arbitrary users via the UserName HTTP header.  Assigned (20160804)  None (candidate not yet proposed)    View
93424  CVE-2016-6604  Candidate  NULL pointer dereference in Samsung Exynos fimg2d driver for Android L(5.0/5.1) and M(6.0) allows attackers to have unspecified impact via unknown vectors.  Assigned (20160805)  None (candidate not yet proposed)    View
93425  CVE-2016-6605  Candidate  Impala in CDH 5.2.0 through 5.7.2 and 5.8.0 allows remote attackers to bypass Setry authorization.  Assigned (20160805)  None (candidate not yet proposed)    View

Page 18685 of 20943, showing 5 records out of 104715 total, starting on record 93421, ending on 93425

Actions