|
266841
|
8.8 |
HIGH
Network
|
redhat
|
jboss_bpm_suite jboss_enterprise_brms_platform
|
Cross-site request forgery (CSRF) vulnerability in Red Hat JBoss BRMS and BPMS 6 allows remote attackers to hijack the authentication of users for requests that modify instances via a crafted web pag…
|
CWE-352
Origin Validation Error
|
CVE-2016-5401
|
2024-11-21 11:54 |
2017-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266842
|
9.8 |
CRITICAL
Network
|
novell
|
groupwise
|
Integer overflow in the Post Office Agent in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 might allow remote attackers to execute arbitrary code via a long (1) username or (2) password,…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2016-5762
|
2024-11-21 11:54 |
2017-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266843
|
6.1 |
MEDIUM
Network
|
novell
|
groupwise
|
Cross-site scripting (XSS) vulnerability in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 allows remote attackers to inject arbitrary web script or HTML via a crafted email.
|
CWE-79
Cross-site Scripting
|
CVE-2016-5761
|
2024-11-21 11:54 |
2017-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266844
|
6.1 |
MEDIUM
Network
|
novell
|
groupwise
|
Multiple cross-site scripting (XSS) vulnerabilities in the administrator console in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 allow remote attackers to inject arbitrary web script or…
|
CWE-79
Cross-site Scripting
|
CVE-2016-5760
|
2024-11-21 11:54 |
2017-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266845
|
7.5 |
HIGH
Network
|
redhat
|
openshift
|
Red Hat OpenShift Enterprise 2 does not include the HTTPOnly flag in a Set-Cookie header for the GEARID cookie, which makes it easier for remote attackers to obtain potentially sensitive information …
|
CWE-200
Information Exposure
|
CVE-2016-5409
|
2024-11-21 11:54 |
2017-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266846
|
5.5 |
MEDIUM
Local
|
firewalld redhat
|
firewalld enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_hpc_node
|
firewalld.py in firewalld before 0.4.3.3 allows local users to bypass authentication and modify firewall configurations via the (1) addPassthrough, (2) removePassthrough, (3) addEntry, (4) removeEntr…
|
CWE-287
Improper Authentication
|
CVE-2016-5410
|
2024-11-21 11:54 |
2017-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266847
|
7.5 |
HIGH
Network
|
apache
|
traffic_server
|
Apache Traffic Server 6.0.0 to 6.2.0 are affected by an HPACK Bomb Attack.
|
CWE-399
Resource Management Errors
|
CVE-2016-5396
|
2024-11-21 11:54 |
2017-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266848
|
6.5 |
MEDIUM
Network
|
symantec
|
messaging_gateway
|
Directory traversal vulnerability in the charting component in Symantec Messaging Gateway before 10.6.2 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the sn paramete…
|
CWE-22
Path Traversal
|
CVE-2016-5312
|
2024-11-21 11:54 |
2017-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266849
|
5.5 |
MEDIUM
Local
|
symantec broadcom
|
protection_engine protection_for_sharepoint_servers mail_security_for_microsoft_exchange messaging_gateway mail_security_for_domino endpoint_protection endpoint_protection_for_small…
|
The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP); Symantec Email Security.Cloud; Symantec Data Center Security: Server; Symantec …
|
CWE-787
Out-of-bounds Write
|
CVE-2016-5310
|
2024-11-21 11:54 |
2017-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266850
|
5.5 |
MEDIUM
Local
|
symantec broadcom
|
protection_engine protection_for_sharepoint_servers mail_security_for_microsoft_exchange messaging_gateway mail_security_for_domino endpoint_protection endpoint_protection_for_small…
|
The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP); Symantec Email Security.Cloud; Symantec Data Center Security: Server; Symantec …
|
CWE-125
Out-of-bounds Read
|
CVE-2016-5309
|
2024-11-21 11:54 |
2017-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|