|
267081
|
5.4 |
MEDIUM
Network
|
ibm
|
websphere_portal
|
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.x through 7.0.0.2 CF30, 8.0.0.x through 8.0.0.1 CF21, and 8.5.0 before C…
|
CWE-79
Cross-site Scripting
|
CVE-2016-2925
|
2024-11-21 11:49 |
2016-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267082
|
5.4 |
MEDIUM
Network
|
ibm
|
rational_publishing_engine
|
Unrestricted file upload vulnerability in the Document Builder in IBM Rational Publishing Engine (aka RPENG) 2.0.1 before ifix002 allows remote authenticated users to execute arbitrary code by specif…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2016-2914
|
2024-11-21 11:49 |
2016-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267083
|
5.4 |
MEDIUM
Network
|
ibm
|
rational_publishing_engine
|
Cross-site scripting (XSS) vulnerability in the Document Builder in IBM Rational Publishing Engine (aka RPENG) 2.0.1 before ifix002 allows remote authenticated users to inject arbitrary web script or…
|
CWE-79
Cross-site Scripting
|
CVE-2016-2912
|
2024-11-21 11:49 |
2016-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267084
|
9.8 |
CRITICAL
Network
|
php
|
php
|
Double free vulnerability in the SplDoublyLinkedList::offsetSet function in ext/spl/spl_dllist.c in PHP 7.x before 7.0.6 allows remote attackers to execute arbitrary code via a crafted index.
|
CWE-415
Double Free
|
CVE-2016-3132
|
2024-11-21 11:49 |
2016-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267085
|
9.8 |
CRITICAL
Network
|
php
|
php
|
Multiple integer overflows in php_zip.c in the zip extension in PHP before 7.0.6 allow remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly hav…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2016-3078
|
2024-11-21 11:49 |
2016-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267086
|
7.8 |
HIGH
Local
|
debian linux
|
debian_linux linux_kernel
|
The trace_writeback_dirty_page implementation in include/trace/events/writeback.h in the Linux kernel before 4.4 improperly interacts with mm/migrate.c, which allows local users to cause a denial of …
|
CWE-476
NULL Pointer Dereference
|
CVE-2016-3070
|
2024-11-21 11:49 |
2016-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267087
|
5.4 |
MEDIUM
Network
|
fortinet
|
fortimanager_firmware fortianalyzer_firmware
|
Cross-site scripting (XSS) vulnerability in Fortinet FortiAnalyzer 5.x before 5.0.12 and 5.2.x before 5.2.6 and FortiManager 5.x before 5.0.12 and 5.2.x before 5.2.6 allows remote authenticated users…
|
CWE-79
Cross-site Scripting
|
CVE-2016-3196
|
2024-11-21 11:49 |
2016-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267088
|
6.1 |
MEDIUM
Network
|
redhat
|
satellite
|
Cross-site scripting (XSS) vulnerability in spacewalk-java in Red Hat Satellite 5.7 allows remote attackers to inject arbitrary web script or HTML via a group name, related to viewing snapshot data.
|
CWE-79
Cross-site Scripting
|
CVE-2016-3097
|
2024-11-21 11:49 |
2016-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267089
|
6.1 |
MEDIUM
Network
|
redhat
|
satellite
|
Cross-site scripting (XSS) vulnerability in spacewalk-java in Red Hat Satellite 5.7 allows remote attackers to inject arbitrary web script or HTML via the (1) RHNMD User or (2) Filesystem parameters,…
|
CWE-79
Cross-site Scripting
|
CVE-2016-3080
|
2024-11-21 11:49 |
2016-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267090
|
6.5 |
MEDIUM
Network
|
mit
|
kerberos_5
|
The validate_as_request function in kdc_util.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.13.6 and 1.4.x before 1.14.3, when restrict_anonymous_to_tgt is enabled, uses…
|
CWE-476
NULL Pointer Dereference
|
CVE-2016-3120
|
2024-11-21 11:49 |
2016-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|