CVE-2016-6465

CVSS v3 Score
4.3
Medium
CVSS v2 Score
4.3
Medium

Vulnerability Description

A vulnerability in the content filtering functionality of Cisco AsyncOS Software for Cisco Email Security Appliances and Cisco Web Security Appliances could allow an unauthenticated, remote attacker to bypass user filters that are configured for an affected device. Affected Products: This vulnerability affects all releases prior to the first fixed release of Cisco AsyncOS Software for both virtual and hardware versions of the following Cisco products: Cisco Email Security Appliances (ESAs) that are configured to use message or content filters that scan incoming email attachments; Cisco Web Security Appliances (WSAs) that are configured to use services that scan accessed web content. More Information: CSCva90076, CSCvb06764. Known Affected Releases: 10.0.0-125 8.5.7-042 9.7.2-047.

CVSS:4.3(Medium)

The CreateID function in packet.py in pyrad before 2.1 uses sequential packet IDs, which makes it easier for remote attackers to spoof packets by predicting the next ID, a different vulnerability than...

CWE-202013
CVSS:4.3(Medium)

An access control issue in MantisBT before 1.2.13 allows users with "Reporter" permissions to change any issue to "New".

CWE-202013
CVSS:4.3(Medium)

MantisBT 1.2.12 before 1.2.15 allows authenticated users to by the workflow restriction and close issues.

CWE-202013
CVSS:4.3(Medium)

ASUS Japan WL-330NUL devices with firmware before 3.0.0.42 allow remote attackers to cause a denial of service via unspecified vectors.

CWE-202015
CVSS:4.3(Medium)

Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka "Internet Explorer Elevation of Privilege Vulnerability."

CWE-202016
CVSS:4.3(Medium)

IBM DB2 9.7 through FP11, 9.8, 10.1 through FP5, and 10.5 through FP7 on Linux, UNIX, and Windows allows remote authenticated users to cause a denial of service (daemon crash) via a crafted DRDA messa...

CWE-202016