|
266411
|
6.5 |
MEDIUM
Network
|
mmonit
|
monit
|
Monit before version 5.20.0 is vulnerable to a cross site request forgery attack. Successful exploitation will enable an attacker to disable/enable all monitoring for a particular host or disable/ena…
|
CWE-352
Origin Validation Error
|
CVE-2016-7067
|
2024-11-21 11:57 |
2018-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266412
|
8.1 |
HIGH
Network
|
postgresql
|
postgresql
|
The interactive installer in PostgreSQL before 9.3.15, 9.4.x before 9.4.10, and 9.5.x before 9.5.5 might allow remote attackers to execute arbitrary code by leveraging use of HTTP to download softwar…
|
CWE-284
Improper Access Control
|
CVE-2016-7048
|
2024-11-21 11:57 |
2018-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266413
|
7.8 |
HIGH
Local
|
sudo_project
|
sudo
|
sudo before version 1.8.18p1 is vulnerable to a bypass in the sudo noexec restriction if application run via sudo executed wordexp() C library function with a user supplied argument. A local user per…
|
CWE-77
Command Injection
|
CVE-2016-7076
|
2024-11-21 11:57 |
2018-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266414
|
6.1 |
MEDIUM
Network
|
tiki
|
tikiwiki_cms\/groupware
|
tiki wiki cms groupware <=15.2 has a xss vulnerability, allow attackers steal user's cookie.
|
CWE-79
Cross-site Scripting
|
CVE-2016-7394
|
2024-11-21 11:57 |
2018-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266415
|
7.8 |
HIGH
Local
|
ui
|
unifi_video
|
Ubiquiti UniFi Video before 3.8.0 for Windows uses weak permissions for the installation directory, which allows local users to gain SYSTEM privileges via a Trojan horse taskkill.exe file.
|
CWE-276
Incorrect Default Permissions
|
CVE-2016-6914
|
2024-11-21 11:57 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266416
|
8.1 |
HIGH
Network
|
netapp
|
vasa_provider
|
Versions of VASA Provider for Clustered Data ONTAP prior to 7.0P1 contain a web server that accepts plain text authentication. This could allow an unauthenticated attacker to obtain authentication cr…
|
CWE-255
Credentials Management
|
CVE-2016-6904
|
2024-11-21 11:57 |
2017-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266417
|
7.5 |
HIGH
Network
|
freeipa
|
freeipa
|
FreeIPA uses a default password policy that locks an account after 5 unsuccessful authentication attempts, which allows remote attackers to cause a denial of service by locking out the account in whi…
|
CWE-255
Credentials Management
|
CVE-2016-7030
|
2024-11-21 11:57 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266418
|
7.8 |
HIGH
Local
|
redhat
|
storage_console storage_console_node
|
rhscon-ceph in Red Hat Storage Console 2 x86_64 and Red Hat Storage Console Node 2 x86_64 allows local users to obtain the password as cleartext.
|
CWE-255
Credentials Management
|
CVE-2016-7062
|
2024-11-21 11:57 |
2017-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266419
|
9.8 |
CRITICAL
Network
|
redhat
|
enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_hpc_node
|
SerializableProvider in RESTEasy in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Workstation 7 allows remot…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2016-7050
|
2024-11-21 11:57 |
2017-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266420
|
5.3 |
MEDIUM
Network
|
citrix
|
xenmobile_server
|
Citrix XenMobile Server before 10.5.0.24 allows man-in-the-middle attackers to trigger HTTP 302 redirections via vectors involving the HTTP Host header and a cached page. NOTE: the vendor reports "o…
|
CWE-20
Improper Input Validation
|
CVE-2016-6877
|
2024-11-21 11:57 |
2017-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|