|
266631
|
4.3 |
MEDIUM
Network
|
alinto
|
sogo
|
Incomplete blacklist in SOGo before 2.3.12 and 3.x before 3.1.1 allows remote authenticated users to obtain sensitive information by reading the fields in the (1) ics or (2) XML calendar feeds.
|
CWE-184
Incomplete Blacklist
|
CVE-2016-6189
|
2024-11-21 11:55 |
2017-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266632
|
9.8 |
CRITICAL
Network
|
fedoraproject zend
|
fedora zend_framework
|
The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.19 might allow remote attackers to conduct SQL injection attacks via vectors related to use of the character pa…
|
CWE-89
SQL Injection
|
CVE-2016-6233
|
2024-11-21 11:55 |
2017-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266633
|
6.1 |
MEDIUM
Network
|
ibm
|
resilient
|
IBM Resilient v26.0, v26.1, and v26.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality …
|
CWE-79
Cross-site Scripting
|
CVE-2016-6062
|
2024-11-21 11:55 |
2017-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266634
|
7.5 |
HIGH
Network
|
ibm
|
security_access_manager_for_web_7.0_firmware security_access_manager_for_web_8.0_firmware security_access_manager_for_mobile security_access_manager_9.0_firmware
|
IBM Security Access Manager for Web 7.0.0, 8.0.0, and 9.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM Reference #: 1…
|
CWE-326
Inadequate Encryption Strength
|
CVE-2016-5919
|
2024-11-21 11:55 |
2017-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266635
|
7.8 |
HIGH
Local
|
ibm
|
aix vios
|
IBM AIX 5.3, 6.1, 7.1, and 7.2 contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privileges. IBM APARs: IV88658, IV87981, IV88419, IV87640, IV88…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-6079
|
2024-11-21 11:55 |
2017-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266636
|
5.3 |
MEDIUM
Local
|
ibm
|
cognos_disclosure_management
|
IBM Cognos Disclosure Management 10.2 could allow a malicious attacker to execute commands as a lower privileged user that opens a malicious document. IBM Reference #: 1991584.
|
CWE-284
Improper Access Control
|
CVE-2016-6077
|
2024-11-21 11:55 |
2017-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266637
|
4.3 |
MEDIUM
Network
|
ibm
|
rational_requirements_composer rational_doors_next_generation
|
An undisclosed vulnerability in IBM Rational DOORS Next Generation 4.0, 5.0, and 6.0 could allow a JazzGuest user to see project names. IBM Reference #: 1995547.
|
CWE-200
Information Exposure
|
CVE-2016-6060
|
2024-11-21 11:55 |
2017-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266638
|
8.8 |
HIGH
Network
|
ibm
|
tivoli_storage_manager_for_virtual_environments_data_protection_for_vmware tivoli_storage_flashcopy_manager_for_vmware
|
IBM Tivoli Storage Manager for Virtual Environments 7.1 (VMware) is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted fr…
|
CWE-352
Origin Validation Error
|
CVE-2016-6033
|
2024-11-21 11:55 |
2017-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266639
|
9.8 |
CRITICAL
Network
|
schneider-electric
|
powerlogic_pm8ecc_firmware
|
An issue was discovered in Schneider Electric PowerLogic PM8ECC device 2.651 and older. Undocumented hard-coded credentials allow access to the device.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2016-5818
|
2024-11-21 11:55 |
2017-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266640
|
9.8 |
CRITICAL
Network
|
schneider-electric
|
ion7600 ion7300 ion8650 ion7500 ion5000 ion8800
|
An issue was discovered on Schneider Electric IONXXXX series power meters ION73XX series, ION75XX series, ION76XX series, ION8650 series, ION8800 series, and PM5XXX series. No authentication is confi…
|
CWE-284
Improper Access Control
|
CVE-2016-5815
|
2024-11-21 11:55 |
2017-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|