|
267171
|
8.8 |
HIGH
Network
|
katello redhat
|
katello satellite
|
Multiple SQL injection vulnerabilities in the scoped_search function in app/controllers/katello/api/v2/api_controller.rb in Katello allow remote authenticated users to execute arbitrary SQL commands …
|
CWE-89
SQL Injection
|
CVE-2016-3072
|
2024-11-21 11:49 |
2016-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267172
|
7.8 |
HIGH
Local
|
fedoraproject redhat
|
fedora ansible
|
The create_script function in the lxc_container module in Ansible before 1.9.6-1 and 2.x before 2.0.2.0 allows local users to write to arbitrary files or gain privileges via a symlink attack on (1) /…
|
CWE-59
Link Following
|
CVE-2016-3096
|
2024-11-21 11:49 |
2016-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267173
|
5.9 |
MEDIUM
Network
|
apache
|
qpid_broker-j
|
PlainSaslServer.java in Apache Qpid Java before 6.0.3, when the broker is configured to allow plaintext passwords, allows remote attackers to cause a denial of service (broker termination) via a craf…
|
CWE-287 CWE-20
Improper Authentication Improper Input Validation
|
CVE-2016-3094
|
2024-11-21 11:49 |
2016-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267174
|
7.5 |
HIGH
Network
|
opensuse gnu fedoraproject canonical
|
opensuse glibc fedora ubuntu_linux
|
Stack-based buffer overflow in the nss_dns implementation of the getnetbyname function in GNU C Library (aka glibc) before 2.24 allows context-dependent attackers to cause a denial of service (stack …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-3075
|
2024-11-21 11:49 |
2016-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267175
|
7.1 |
HIGH
Local
|
php
|
php
|
The make_http_soap_request function in ext/soap/php_http.c in PHP before 5.4.44, 5.5.x before 5.5.28, 5.6.x before 5.6.12, and 7.x before 7.0.4 allows remote attackers to obtain sensitive information…
|
CWE-20
Improper Input Validation
|
CVE-2016-3185
|
2024-11-21 11:49 |
2016-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267176
|
8.8 |
HIGH
Network
|
debian mercurial
|
debian_linux mercurial
|
The convert extension in Mercurial before 3.8 might allow context-dependent attackers to execute arbitrary code via a crafted git repository name.
|
CWE-284
Improper Access Control
|
CVE-2016-3105
|
2024-11-21 11:49 |
2016-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267177
|
4.6 |
MEDIUM
Physics
|
canonical linux novell
|
ubuntu_linux linux_kernel suse_linux_enterprise_module_for_public_cloud suse_linux_enterprise_server suse_linux_enterprise_live_patching suse_linux_enterprise_real_time_extension su…
|
The digi_port_init function in drivers/usb/serial/digi_acceleport.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and s…
|
NVD-CWE-Other
|
CVE-2016-3140
|
2024-11-21 11:49 |
2016-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267178
|
4.6 |
MEDIUM
Physics
|
linux canonical novell
|
linux_kernel ubuntu_linux suse_linux_enterprise_module_for_public_cloud suse_linux_enterprise_server suse_linux_enterprise_live_patching suse_linux_enterprise_real_time_extension su…
|
The acm_probe function in drivers/usb/class/cdc-acm.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) v…
|
NVD-CWE-Other
|
CVE-2016-3138
|
2024-11-21 11:49 |
2016-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267179
|
4.6 |
MEDIUM
Physics
|
novell canonical linux
|
suse_linux_enterprise_module_for_public_cloud suse_linux_enterprise_server suse_linux_enterprise_live_patching suse_linux_enterprise_real_time_extension suse_linux_enterprise_desktop s…
|
drivers/usb/serial/cypress_m8.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a USB device withou…
|
NVD-CWE-Other
|
CVE-2016-3137
|
2024-11-21 11:49 |
2016-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267180
|
4.6 |
MEDIUM
Physics
|
linux novell canonical
|
linux_kernel suse_linux_enterprise_module_for_public_cloud suse_linux_enterprise_server suse_linux_enterprise_live_patching suse_linux_enterprise_desktop suse_linux_enterprise_real_tim…
|
The mct_u232_msr_to_state function in drivers/usb/serial/mct_u232.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and s…
|
NVD-CWE-Other
|
CVE-2016-3136
|
2024-11-21 11:49 |
2016-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|