|
267461
|
6.1 |
MEDIUM
Network
|
ibm
|
security_access_manager security_access_manager_for_mobile security_access_manager_for_web
|
IBM Security Access Manager for Web is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality po…
|
CWE-79
Cross-site Scripting
|
CVE-2016-3018
|
2024-11-21 11:49 |
2017-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267462
|
7.5 |
HIGH
Network
|
ibm
|
security_access_manager_9.0_firmware security_access_manager_for_mobile_8.0_firmware security_access_manager_for_web_7.0_firmware security_access_manager_for_web_8.0_firmware
|
IBM Security Access Manager for Web could allow a remote attacker to obtain sensitive information due to security misconfigurations.
|
CWE-358
Improperly Implemented Security Check for Standard
|
CVE-2016-3017
|
2024-11-21 11:49 |
2017-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267463
|
4.4 |
MEDIUM
Network
|
ibm
|
security_access_manager_9.0_firmware security_access_manager_for_mobile_8.0_firmware security_access_manager_for_web_7.0_firmware security_access_manager_for_web_8.0_firmware
|
IBM Security Access Manager for Web processes patches, image backups and other updates without sufficiently verifying the origin and integrity of the code, which could allow an authenticated attacker…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2016-3016
|
2024-11-21 11:49 |
2017-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267464
|
4.3 |
MEDIUM
Network
|
ibm
|
rational_rhapsody_design_manager rational_software_architect_design_manager rational_quality_manager rational_team_concert rational_doors_next_generation rational_engineering_lifecycle…
|
An undisclosed vulnerability in CLM applications may result in some administrative deployment parameters being shown to an attacker.
|
CWE-200
Information Exposure
|
CVE-2016-2987
|
2024-11-21 11:49 |
2017-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267465
|
6.1 |
MEDIUM
Network
|
ibm
|
inotes domino
|
IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cred…
|
CWE-79
Cross-site Scripting
|
CVE-2016-2939
|
2024-11-21 11:49 |
2017-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267466
|
6.1 |
MEDIUM
Network
|
ibm
|
inotes domino
|
IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cred…
|
CWE-79
Cross-site Scripting
|
CVE-2016-2938
|
2024-11-21 11:49 |
2017-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267467
|
9.1 |
CRITICAL
Network
|
ibm
|
security_access_manager_9.0_firmware security_access_manager_for_mobile_8.0_firmware security_access_manager_for_web_8.0_firmware
|
IBM Single Sign On for Bluemix could allow a remote attacker to obtain sensitive information, caused by a XML external entity (XXE) error when processing XML data by the XML parser. A remote attacker…
|
CWE-611
XXE
|
CVE-2016-2908
|
2024-11-21 11:49 |
2017-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267468
|
5.6 |
MEDIUM
Network
|
saltstack
|
salt
|
Salt before 2015.5.10 and 2015.8.x before 2015.8.8, when PAM external authentication is enabled, allows attackers to bypass the configured authentication service by passing an alternate service with …
|
CWE-287
Improper Authentication
|
CVE-2016-3176
|
2024-11-21 11:49 |
2017-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267469
|
9.8 |
CRITICAL
Network
|
giflib_project
|
giflib
|
Multiple use-after-free and double-free vulnerabilities in gifcolor.c in GIFLIB 5.1.2 have unspecified impact and attack vectors.
|
CWE-415 CWE-416
Double Free Use After Free
|
CVE-2016-3177
|
2024-11-21 11:49 |
2017-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267470
|
9.8 |
CRITICAL
Network
|
ivanti
|
landesk_management_suite
|
Buffer overflow in the collector.exe listener of the Landesk Management Suite 10.0.0.271 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a lar…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-3147
|
2024-11-21 11:49 |
2017-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|