Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2016-08-31 CVE-2016-5678 Use of Hard-coded Credentials vulnerability in Nuuo Nvrmini 2 and Nvrsolo
NUUO NVRmini 2 1.0.0 through 3.0.0 and NUUO NVRsolo 1.0.0 through 3.0.0 have hardcoded root credentials, which allows remote attackers to obtain administrative access via unspecified vectors.
network
low complexity
nuuo CWE-798
critical
9.8
2016-08-31 CVE-2016-5677 Information Exposure vulnerability in multiple products
NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 have a hardcoded qwe23622260 password for the nuuoeng account, which allows remote attackers to obtain sensitive information via an __nvr_status___.php request.
network
low complexity
netgear nuuo CWE-200
7.5
2016-08-31 CVE-2016-5676 Improper Authorization vulnerability in multiple products
cgi-bin/cgi_system in NUUO NVRmini 2 1.7.5 through 2.x, NUUO NVRsolo 1.7.5 through 2.x, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to reset the administrator password via a cmd=loaddefconfig action.
network
low complexity
netgear nuuo CWE-285
7.5
2016-08-31 CVE-2016-5675 Improper Input Validation vulnerability in multiple products
handle_daylightsaving.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, NUUO Crystal 2.2.1 through 3.2.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to execute arbitrary PHP code via the NTPServer parameter.
network
low complexity
netgear nuuo CWE-20
critical
9.8
2016-08-31 CVE-2016-5674 Improper Input Validation vulnerability in multiple products
__debugging_center_utils___.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.7.5 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to execute arbitrary PHP code via the log parameter.
network
low complexity
netgear nuuo CWE-20
critical
9.8
2016-08-31 CVE-2016-7119 Cross-site Scripting vulnerability in Dotnetnuke
Cross-site scripting (XSS) vulnerability in the user-profile biography section in DotNetNuke (DNN) before 8.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted onclick attribute in an IMG element.
network
low complexity
dotnetnuke CWE-79
5.4
2016-08-31 CVE-2016-7118 NULL Pointer Dereference vulnerability in Debian Linux 7.0
fs/fcntl.c in the "aufs 3.2.x+setfl-debian" patch in the linux-image package 3.2.0-4 (kernel 3.2.81-1) in Debian wheezy mishandles F_SETFL fcntl calls on directories, which allows local users to cause a denial of service (NULL pointer dereference and system crash) via standard filesystem operations, as demonstrated by scp from an AUFS filesystem.
local
low complexity
debian CWE-476
5.5
2016-08-31 CVE-2016-5336 Unspecified vulnerability in VMWare Vrealize Automation 7.0/7.0.1
VMware vRealize Automation 7.0.x before 7.1 allows remote attackers to execute arbitrary code via unspecified vectors.
network
low complexity
vmware
critical
9.8
2016-08-31 CVE-2016-5335 Unspecified vulnerability in VMWare Identity Manager and Vrealize Automation
VMware Identity Manager 2.x before 2.7 and vRealize Automation 7.0.x before 7.1 allow local users to obtain root access via unspecified vectors.
local
low complexity
vmware
7.8
2016-08-31 CVE-2016-5333 Use of Hard-coded Credentials vulnerability in VMWare Photon OS 1.0
VMware Photos OS OVA 1.0 before 2016-08-14 has a default SSH public key in an authorized_keys file, which allows remote attackers to obtain SSH access by leveraging knowledge of the private key.
network
low complexity
vmware CWE-798
critical
9.8