|
266911
|
3.3 |
LOW
Local
|
redhat
|
enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_hpc_node subscription-manager
|
The Subscription Manager package (aka subscription-manager) before 1.17.7-1 for Candlepin uses weak permissions (755) for subscription-manager cache directories, which allows local users to obtain se…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-4455
|
2024-11-21 11:52 |
2017-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266912
|
7.5 |
HIGH
Network
|
redhat
|
mod_cluster enterprise_linux
|
Stack-based buffer overflow in native/mod_manager/node.c in mod_cluster 1.2.9.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-4459
|
2024-11-21 11:52 |
2017-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266913
|
7.0 |
HIGH
Local
|
setroubleshoot_project redhat
|
setroubleshoot enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_hpc_node
|
The allow_execstack plugin for setroubleshoot allows local users to execute arbitrary commands by triggering an execstack SELinux denial with a crafted filename, related to the commands.getoutput fun…
|
CWE-77
Command Injection
|
CVE-2016-4446
|
2024-11-21 11:52 |
2017-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266914
|
7.0 |
HIGH
Local
|
setroubleshoot_project redhat
|
setroubleshoot enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_hpc_node
|
The fix_lookup_id function in sealert in setroubleshoot before 3.2.23 allows local users to execute arbitrary commands as root by triggering an SELinux denial with a crafted file name, related to exe…
|
CWE-77
Command Injection
|
CVE-2016-4445
|
2024-11-21 11:52 |
2017-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266915
|
7.0 |
HIGH
Local
|
setroubleshoot_project redhat
|
setroubleshoot enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_hpc_node
|
The allow_execmod plugin for setroubleshoot before 3.2.23 allows local users to execute arbitrary commands by triggering an execmod SELinux denial with a crafted binary filename, related to the comma…
|
CWE-77
Command Injection
|
CVE-2016-4444
|
2024-11-21 11:52 |
2017-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266916
|
7.5 |
HIGH
Network
|
xmlsoft debian oracle
|
libxml2 debian_linux solaris
|
The xmlBufAttrSerializeTxtContent function in xmlsave.c in libxml2 allows context-dependent attackers to cause a denial of service (out-of-bounds read and application crash) via a non-UTF-8 attribute…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2016-4483
|
2024-11-21 11:52 |
2017-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266917
|
8.8 |
HIGH
Network
|
pivotal_software cloudfoundry
|
cloud_foundry_elastic_runtime cloud_foundry cloud_foundry_uaa cloud_foundry_ops_manager cloud_foundry_uaa_bosh
|
SQL injection vulnerability in Pivotal Cloud Foundry (PCF) before 238; UAA 2.x before 2.7.4.4, 3.x before 3.3.0.2, and 3.4.x before 3.4.1; UAA BOSH before 11.2 and 12.x before 12.2; Elastic Runtime b…
|
CWE-89
SQL Injection
|
CVE-2016-4468
|
2024-11-21 11:52 |
2017-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266918
|
8.8 |
HIGH
Network
|
meteocontrol
|
weblog
|
A Cross-Site Request Forgery issue was discovered in Meteocontrol WEB'log Basic 100 all versions, Light all versions, Pro all versions, and Pro Unlimited all versions. There is no CSRF Token generate…
|
CWE-352
Origin Validation Error
|
CVE-2016-4504
|
2024-11-21 11:52 |
2017-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266919
|
5.5 |
MEDIUM
Local
|
gnu
|
libiberty
|
The demangle_template_value_parm and do_hpacc_template_literal functions in cplus-dem.c in libiberty allow remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted b…
|
CWE-125
Out-of-bounds Read
|
CVE-2016-4493
|
2024-11-21 11:52 |
2017-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266920
|
4.4 |
MEDIUM
Local
|
gnu
|
libiberty
|
Buffer overflow in the do_type function in cplus-dem.c in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-4492
|
2024-11-21 11:52 |
2017-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|