|
266461
|
7.0 |
HIGH
Local
|
redhat
|
satellite
|
discovery-debug in Foreman before 6.2 when the ssh service has been enabled on discovered nodes displays the root password in plaintext in the system journal when used to log in, which allows local u…
|
CWE-255
Credentials Management
|
CVE-2016-4996
|
2024-11-21 11:53 |
2017-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266462
|
4.7 |
MEDIUM
Local
|
openldap
|
openldap-servers
|
/usr/libexec/openldap/generate-server-cert.sh in openldap-servers sets weak permissions for the TLS certificate, which allows local users to obtain the TLS certificate by leveraging a race condition …
|
CWE-362
Race Condition
|
CVE-2016-4984
|
2024-11-21 11:53 |
2017-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266463
|
4.7 |
MEDIUM
Local
|
teether
|
authd
|
authd sets weak permissions for /etc/ident.key, which allows local users to obtain the key by leveraging a race condition between the creation of the key, and the chmod to protect it.
|
CWE-362
Race Condition
|
CVE-2016-4982
|
2024-11-21 11:53 |
2017-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266464
|
8.1 |
HIGH
Network
|
netapp
|
oncommand_system_manager
|
NetApp OnCommand System Manager before 9.0 allows remote attackers to obtain sensitive credentials via vectors related to cluster peering setup.
|
CWE-200
Information Exposure
|
CVE-2016-5045
|
2024-11-21 11:53 |
2017-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266465
|
4.3 |
MEDIUM
Network
|
cybozu
|
garoon
|
Cybozu Garoon 3.0.0 to 4.2.2 allows remote authenticated attackers to bypass access restriction to delete other operational administrators' MultiReport filters via unspecified vectors.
|
CWE-284
Improper Access Control
|
CVE-2016-4910
|
2024-11-21 11:53 |
2017-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266466
|
4.3 |
MEDIUM
Network
|
cybozu
|
garoon
|
Cross-site request forgery (CSRF) vulnerability in Cybozu Garoon 3.0.0 to 4.2.2 allows remote attackers to hijack the authentication of a logged in user to force a logout via unspecified vectors.
|
CWE-352
Origin Validation Error
|
CVE-2016-4909
|
2024-11-21 11:53 |
2017-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266467
|
4.3 |
MEDIUM
Network
|
cybozu
|
garoon
|
Cybozu Garoon 3.0.0 to 4.2.2 allows remote authenticated attackers to bypass access restriction to alter or delete another user's private RSS settings via unspecified vectors.
|
CWE-284
Improper Access Control
|
CVE-2016-4908
|
2024-11-21 11:53 |
2017-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266468
|
8.8 |
HIGH
Network
|
cybozu
|
garoon
|
Cybozu Garoon 3.0.0 to 4.2.2 allow remote attackers to obtain CSRF tokens via unspecified vectors.
|
CWE-352
Origin Validation Error
|
CVE-2016-4907
|
2024-11-21 11:53 |
2017-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266469
|
6.1 |
MEDIUM
Network
|
cybozu
|
garoon
|
Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.2.2 allows remote attackers to inject arbitrary web script or HTML via "Messages" function of Cybozu Garoon Keitai.
|
CWE-79
Cross-site Scripting
|
CVE-2016-4906
|
2024-11-21 11:53 |
2017-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266470
|
7.8 |
HIGH
Local
|
jpki
|
the_public_certification_service_for_individuals the_public_certification_service_for_individuals_for_windows_vista the_public_certification_service_for_individuals_for_windows_7
|
Untrusted search path vulnerability in The Public Certification Service for Individuals "The JPKI user's software (for Windows 7 and later)" Ver3.0.1 and earlier, The Public Certification Service for…
|
CWE-426
Untrusted Search Path
|
CVE-2016-4902
|
2024-11-21 11:53 |
2017-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|