CloudView NMS before 2.10a has a format string issue exploitable over SNMP.
Category Archives: Security
Security
CVE-2016-5055
OSRAM SYLVANIA Osram Lightify Pro before 2016-07-26 has XSS in the username field and Wireless Client Mode configuration page.
CVE-2015-7265
Facebook Proxygen before 2015-11-09 mismanages HTTPMessage.request state, which allows remote attackers to conduct hijacking attacks and bypass ACL checks.
CVE-2016-4317
Atlassian Confluence Server before 5.9.11 has XSS on the viewmyprofile.action page.
CVE-2015-2886
iBaby M6 allows remote attackers to obtain sensitive information, related to the ibabycloud.com service.
CVE-2016-6534
Opmantek NMIS before 4.3.7c has command injection via man, finger, ping, trace, and nslookup in the tools.pl CGI script. Versions before 8.5.12G might be affected in non-default configurations.
CVE-2016-5073
CloudView NMS before 2.10a has XSS via SNMP.
CVE-2016-5057
OSRAM SYLVANIA Osram Lightify Pro through 2016-07-26 does not use SSL pinning.
CVE-2015-6035
Opsview before 2015-11-06 has XSS via SNMP.
CVE-2016-4319
Atlassian JIRA Server before 7.1.9 has CSRF in auditing/settings.