|
268411
|
9.8 |
CRITICAL
Network
|
redhat
|
jboss_operations_network
|
The server in Red Hat JBoss Operations Network (JON), when SSL authentication is not configured for JON server / agent communication, allows remote attackers to execute arbitrary code via a crafted H…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2016-6330
|
2024-11-21 11:55 |
2016-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268412
|
5.3 |
MEDIUM
Network
|
sap
|
trex
|
The NameServer in SAP TREX 7.10 Revision 63 allows remote attackers to obtain sensitive TNS information via an unspecified query, aka SAP Security Note 2234226.
|
CWE-200
Information Exposure
|
CVE-2016-6146
|
2024-11-21 11:55 |
2016-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268413
|
9.8 |
CRITICAL
Network
|
sap
|
trex
|
An unspecified function in SAP TREX 7.10 Revision 63 allows remote attackers to execute arbitrary OS commands via unknown vectors, aka SAP Security Note 2203591.
|
NVD-CWE-noinfo
|
CVE-2016-6137
|
2024-11-21 11:55 |
2016-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268414
|
9.8 |
CRITICAL
Network
|
openssl
|
openssl
|
statem/statem.c in OpenSSL 1.1.0a does not consider memory-block movement after a realloc call, which allows remote attackers to cause a denial of service (use-after-free) or possibly execute arbitra…
|
CWE-416
Use After Free
|
CVE-2016-6309
|
2024-11-21 11:55 |
2016-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268415
|
5.9 |
MEDIUM
Network
|
openssl
|
openssl
|
statem/statem_dtls.c in the DTLS implementation in OpenSSL 1.1.0 before 1.1.0a allocates memory before checking for an excessive length, which might allow remote attackers to cause a denial of servic…
|
CWE-399
Resource Management Errors
|
CVE-2016-6308
|
2024-11-21 11:55 |
2016-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268416
|
5.9 |
MEDIUM
Network
|
openssl
|
openssl
|
The state-machine implementation in OpenSSL 1.1.0 before 1.1.0a allocates memory before checking for an excessive length, which might allow remote attackers to cause a denial of service (memory consu…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2016-6307
|
2024-11-21 11:55 |
2016-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268417
|
5.9 |
MEDIUM
Network
|
openssl hp novell nodejs debian canonical
|
openssl icewall_sso icewall_mcrp icewall_sso_agent_option icewall_federation_agent suse_linux_enterprise_module_for_web_scripting node.js debian_linux ubuntu_linux
|
The certificate parser in OpenSSL before 1.0.1u and 1.0.2 before 1.0.2i might allow remote attackers to cause a denial of service (out-of-bounds read) via crafted certificate operations, related to s…
|
CWE-125
Out-of-bounds Read
|
CVE-2016-6306
|
2024-11-21 11:55 |
2016-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268418
|
7.5 |
HIGH
Network
|
openssl
|
openssl
|
The ssl3_read_bytes function in record/rec_layer_s3.c in OpenSSL 1.1.0 before 1.1.0a allows remote attackers to cause a denial of service (infinite loop) by triggering a zero-length record in an SSL_…
|
CWE-20
Improper Input Validation
|
CVE-2016-6305
|
2024-11-21 11:55 |
2016-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268419
|
7.5 |
HIGH
Network
|
openssl nodejs novell
|
openssl node.js suse_linux_enterprise_module_for_web_scripting
|
Multiple memory leaks in t1_lib.c in OpenSSL before 1.0.1u, 1.0.2 before 1.0.2i, and 1.1.0 before 1.1.0a allow remote attackers to cause a denial of service (memory consumption) via large OCSP Status…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2016-6304
|
2024-11-21 11:55 |
2016-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268420
|
6.5 |
MEDIUM
Network
|
ibm
|
aix
|
Directory traversal vulnerability in Eclipse Help in IBM Tivoli Lightweight Infrastructure (aka LWI), as used in AIX 5.3, 6.1, and 7.1, allows remote authenticated users to read arbitrary files via a…
|
CWE-22
Path Traversal
|
CVE-2016-6038
|
2024-11-21 11:55 |
2016-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|