|
267421
|
8.8 |
HIGH
Network
|
cybozu
|
garoon
|
Cybozu Garoon 3.0.0 to 4.2.2 allow remote attackers to obtain CSRF tokens via unspecified vectors.
|
CWE-352
Origin Validation Error
|
CVE-2016-4907
|
2024-11-21 11:53 |
2017-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267422
|
6.1 |
MEDIUM
Network
|
cybozu
|
garoon
|
Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.2.2 allows remote attackers to inject arbitrary web script or HTML via "Messages" function of Cybozu Garoon Keitai.
|
CWE-79
Cross-site Scripting
|
CVE-2016-4906
|
2024-11-21 11:53 |
2017-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267423
|
7.8 |
HIGH
Local
|
jpki
|
the_public_certification_service_for_individuals the_public_certification_service_for_individuals_for_windows_vista the_public_certification_service_for_individuals_for_windows_7
|
Untrusted search path vulnerability in The Public Certification Service for Individuals "The JPKI user's software (for Windows 7 and later)" Ver3.0.1 and earlier, The Public Certification Service for…
|
CWE-426
Untrusted Search Path
|
CVE-2016-4902
|
2024-11-21 11:53 |
2017-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267424
|
7.5 |
HIGH
Network
|
redhat
|
enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_hpc_node
|
389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server 6 through 7, and Red Hat Enterprise Linux Workstat…
|
CWE-200
Information Exposure
|
CVE-2016-4992
|
2024-11-21 11:53 |
2017-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267425
|
7.8 |
HIGH
Local
|
gnu
|
libssp
|
Binaries compiled against targets that use the libssp library in GCC for stack smashing protection (SSP) might allow local users to perform buffer overflow attacks by leveraging lack of the Object Si…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-4973
|
2024-11-21 11:53 |
2017-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267426
|
6.5 |
MEDIUM
Network
|
apache
|
ws-xmlrpc
|
The Content-Encoding HTTP header feature in ws-xmlrpc 3.1.3 as used in Apache Archiva allows remote attackers to cause a denial of service (resource consumption) by decompressing a large file contain…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2016-5004
|
2024-11-21 11:53 |
2017-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267427
|
8.8 |
HIGH
Network
|
pivotal
|
spring_security_oauth
|
When processing authorization requests using the whitelabel views in Spring Security OAuth 2.0.0 to 2.0.9 and 1.0.0 to 1.0.5, the response_type parameter value was executed as Spring SpEL which enabl…
|
CWE-19
Data Processing Errors
|
CVE-2016-4977
|
2024-11-21 11:53 |
2017-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267428
|
7.5 |
HIGH
Network
|
pivotal_software vmware
|
spring_framework spring_security
|
Both Spring Security 3.2.x, 4.0.x, 4.1.0 and the Spring Framework 3.2.x, 4.0.x, 4.1.x, 4.2.x rely on URL pattern mappings for authorization and for mapping requests to controllers respectively. Diffe…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-5007
|
2024-11-21 11:53 |
2017-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267429
|
9.8 |
CRITICAL
Network
|
google opensuse debian redhat fedoraproject
|
chrome leap opensuse debian_linux enterprise_linux_server_supplementary enterprise_linux_workstation_supplementary fedora
|
Multiple unspecified vulnerabilities in Google Chrome before 53.0.2785.143 allow remote attackers to cause a denial of service or possibly have other impact via unknown vectors.
|
CWE-20
Improper Input Validation
|
CVE-2016-5178
|
2024-11-21 11:53 |
2017-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267430
|
8.8 |
HIGH
Network
|
google opensuse debian redhat fedoraproject
|
chrome leap opensuse debian_linux enterprise_linux_server_supplementary enterprise_linux_workstation_supplementary fedora
|
Use-after-free vulnerability in V8 in Google Chrome before 53.0.2785.143 allows remote attackers to cause a denial of service (crash) or possibly have unspecified other impact via unknown vectors.
|
CWE-416
Use After Free
|
CVE-2016-5177
|
2024-11-21 11:53 |
2017-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|