CVE-2016-8584
Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier uses a predictable session values, which allows remote attackers to bypass authentication by guessing the value.
Read MoreTrend Micro Threat Discovery Appliance 2.6.1062r1 and earlier uses a predictable session values, which allows remote attackers to bypass authentication by guessing the value.
Read MoreThe hotfix_upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code via shell metacharacters in the file name of an uploaded file.
Read Morelog_query_dae.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter.
Read MoreThe LaLa Call App for Android 2.4.7 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Read MoreCross-site request forgery (CSRF) vulnerability in Hands-on Vulnerability Learning Tool “AppGoat” for Web Application V3.0.0 and earlier allows remote attackers to hijack the authentication of administrators via...
Read More