|
268181
|
5.3 |
MEDIUM
Network
|
redhat
|
jboss_a-mq jboss_fuse
|
It was found that the JMX endpoint of Red Hat JBoss Fuse 6, and Red Hat A-MQ 6 deserializes the credentials passed to it. An attacker could use this flaw to launch a denial of service attack.
|
-
|
CVE-2016-8653
|
2024-11-21 11:59 |
2018-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268182
|
7.2 |
HIGH
Network
|
redhat
|
jboss_a-mq jboss_fuse
|
It was found that the Karaf container used by Red Hat JBoss Fuse 6.x, and Red Hat JBoss A-MQ 6.x, deserializes objects passed to MBeans via JMX operations. An attacker could use this flaw to execute …
|
-
|
CVE-2016-8648
|
2024-11-21 11:59 |
2018-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268183
|
7.8 |
HIGH
Local
|
nagios
|
nagios
|
A privilege escalation vulnerability was found in nagios 4.2.x that occurs in daemon-init.in when creating necessary files and insecurely changing the ownership afterwards. It's possible for the loca…
|
-
|
CVE-2016-8641
|
2024-11-21 11:59 |
2018-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268184
|
5.4 |
MEDIUM
Network
|
redhat
|
jboss_bpm_suite jboss_business_rules_management_system
|
JBoss BRMS 6 and BPM Suite 6 are vulnerable to a stored XSS via business process editor. The flaw is due to an incomplete fix for CVE-2016-5398. Remote, authenticated attackers that have privileges t…
|
-
|
CVE-2016-8608
|
2024-11-21 11:59 |
2018-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268185
|
5.4 |
MEDIUM
Network
|
theforeman redhat
|
foreman satellite satellite_capsule
|
It was found that foreman before 1.13.0 is vulnerable to a stored XSS via an organization or location name. This could allow an attacker with privileges to set the organization or location name to di…
|
CWE-79
Cross-site Scripting
|
CVE-2016-8639
|
2024-11-21 11:59 |
2018-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268186
|
7.8 |
HIGH
Local
|
dracut_project
|
dracut
|
A local information disclosure issue was found in dracut before 045 when generating initramfs images with world-readable permissions when 'early cpio' is used, such as when including microcode update…
|
-
|
CVE-2016-8637
|
2024-11-21 11:59 |
2018-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268187
|
5.9 |
MEDIUM
Network
|
mozilla redhat
|
network_security_services enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation enterprise_linux_server_tus enterprise_linux_server_aus enterprise_linux_serv…
|
It was found that Diffie Hellman Client key exchange handling in NSS 3.21.x was vulnerable to small subgroup confinement attack. An attacker could use this flaw to recover private keys by confining t…
|
-
|
CVE-2016-8635
|
2024-11-21 11:59 |
2018-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268188
|
5.4 |
MEDIUM
Network
|
theforeman
|
foreman
|
A vulnerability was found in foreman 1.14.0. When creating an organization or location in Foreman, if the name contains HTML then the second step of the wizard (/organizations/id/step2) will render t…
|
-
|
CVE-2016-8634
|
2024-11-21 11:59 |
2018-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268189
|
7.5 |
HIGH
Network
|
haxx
|
curl
|
curl before version 7.51.0 uses outdated IDNA 2003 standard to handle International Domain Names and this may lead users to potentially and unknowingly issue network transfer requests to the wrong ho…
|
-
|
CVE-2016-8625
|
2024-11-21 11:59 |
2018-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268190
|
7.5 |
HIGH
Network
|
haxx
|
curl
|
A flaw was found in curl before version 7.51.0. The way curl handles cookies permits other threads to trigger a use-after-free leading to information disclosure.
|
-
|
CVE-2016-8623
|
2024-11-21 11:59 |
2018-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|