|
267181
|
9.8 |
CRITICAL
Network
|
f5
|
big-ip_policy_enforcement_manager big-ip_local_traffic_manager big-ip_websafe big-ip_link_controller big-ip_application_acceleration_manager big-ip_access_policy_manager big-ip_adva…
|
Virtual servers in F5 BIG-IP systems 11.5.0, 11.5.1 before HF11, 11.5.2, 11.5.3, 11.5.4 before HF2, 11.6.0 before HF8, 11.6.1 before HF1, 12.0.0 before HF4, and 12.1.0 before HF2, when configured wit…
|
CWE-284
Improper Access Control
|
CVE-2016-5700
|
2024-11-21 11:54 |
2016-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267182
|
5.1 |
MEDIUM
Local
|
opensuse yast
|
libstorage-ng yast-storage libstorage leap
|
libstorage, libstorage-ng, and yast-storage improperly store passphrases for encrypted storage devices in a temporary file on disk, which might allow local users to obtain sensitive information by re…
|
NVD-CWE-Other
|
CVE-2016-5746
|
2024-11-21 11:54 |
2016-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267183
|
8.8 |
HIGH
Network
|
redhat
|
jboss_enterprise_application_platform
|
The domain controller in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2 allows remote authenticated users to gain privileges by leveraging failure to propagate administrative RB…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-5406
|
2024-11-21 11:54 |
2016-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267184
|
4.8 |
MEDIUM
Network
|
apache
|
ranger
|
Cross-site scripting (XSS) vulnerability in the create user functionality in the policy admin tool in Apache Ranger before 0.6.1 allows remote authenticated administrators to inject arbitrary web scr…
|
CWE-79
Cross-site Scripting
|
CVE-2016-5395
|
2024-11-21 11:54 |
2016-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267185
|
7.5 |
HIGH
Network
|
powerdns
|
authoritative
|
PowerDNS (aka pdns) Authoritative Server before 3.4.10 does not properly handle a . (dot) inside labels, which allows remote attackers to cause a denial of service (backend CPU consumption) via a cra…
|
CWE-399
Resource Management Errors
|
CVE-2016-5427
|
2024-11-21 11:54 |
2016-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267186
|
7.5 |
HIGH
Network
|
powerdns
|
authoritative
|
PowerDNS (aka pdns) Authoritative Server before 3.4.10 allows remote attackers to cause a denial of service (backend CPU consumption) via a long qname.
|
CWE-399
Resource Management Errors
|
CVE-2016-5426
|
2024-11-21 11:54 |
2016-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267187
|
7.5 |
HIGH
Network
|
redhat oracle libarchive
|
enterprise_linux_hpc_node enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation linux openshift libarchive enterprise_linux_server_aus enterprise_linux…
|
The sandboxing code in libarchive 3.2.0 and earlier mishandles hardlink archive entries of non-zero data size, which might allow remote attackers to write to arbitrary files via a crafted archive fil…
|
CWE-20 CWE-19
Improper Input Validation Data Processing Errors
|
CVE-2016-5418
|
2024-11-21 11:54 |
2016-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267188
|
6.5 |
MEDIUM
Network
|
freeipa oracle fedoraproject
|
freeipa linux fedora
|
The cert_revoke command in FreeIPA does not check for the "revoke certificate" permission, which allows remote authenticated users to revoke arbitrary certificates by leveraging the "retrieve certifi…
|
CWE-284
Improper Access Control
|
CVE-2016-5404
|
2024-11-21 11:54 |
2016-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267189
|
8.8 |
HIGH
Network
|
redhat
|
jboss_operations_network
|
The web console in Red Hat JBoss Operations Network (JON) before 3.3.7 does not properly authorize requests to add users with the super user role, which allows remote authenticated users to gain admi…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-5422
|
2024-11-21 11:54 |
2016-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267190
|
5.3 |
MEDIUM
Network
|
jose-php_project
|
jose-php
|
The RSA 1.5 algorithm implementation in the JOSE_JWE class in JWE.php in jose-php before 2.2.1 lacks the Random Filling protection mechanism, which makes it easier for remote attackers to obtain clea…
|
CWE-310 CWE-200
Cryptographic Issues Information Exposure
|
CVE-2016-5430
|
2024-11-21 11:54 |
2016-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|