|
269211
|
7.4 |
HIGH
Network
|
jenkins redhat
|
jenkins openshift
|
Multiple open redirect vulnerabilities in Jenkins before 2.3 and LTS before 1.651.2 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vector…
|
NVD-CWE-Other
|
CVE-2016-3726
|
2024-11-21 11:50 |
2016-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269212
|
4.3 |
MEDIUM
Network
|
jenkins redhat
|
jenkins openshift
|
Jenkins before 2.3 and LTS before 1.651.2 allows remote authenticated users to trigger updating of update site metadata by leveraging a missing permissions check. NOTE: this issue can be combined wit…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-3725
|
2024-11-21 11:50 |
2016-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269213
|
6.5 |
MEDIUM
Network
|
redhat jenkins
|
openshift jenkins
|
Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with extended read access to obtain sensitive password information by reading a job configuration.
|
CWE-200
Information Exposure
|
CVE-2016-3724
|
2024-11-21 11:50 |
2016-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269214
|
4.3 |
MEDIUM
Network
|
jenkins redhat
|
jenkins openshift
|
Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with read access to obtain sensitive plugin installation information by leveraging missing permissions checks in unspecified…
|
CWE-200
Information Exposure
|
CVE-2016-3723
|
2024-11-21 11:50 |
2016-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269215
|
4.3 |
MEDIUM
Network
|
jenkins redhat
|
jenkins openshift
|
Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with multiple accounts to cause a denial of service (unable to login) by editing the "full name."
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-3722
|
2024-11-21 11:50 |
2016-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269216
|
6.5 |
MEDIUM
Network
|
redhat jenkins
|
openshift jenkins
|
Jenkins before 2.3 and LTS before 1.651.2 might allow remote authenticated users to inject arbitrary build parameters into the build environment via environment variables.
|
CWE-17
Code
|
CVE-2016-3721
|
2024-11-21 11:50 |
2016-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269217
|
7.5 |
HIGH
Network
|
canonical xmlsoft debian hp opensuse
|
ubuntu_linux libxml2 debian_linux icewall_file_manager icewall_federation_agent leap
|
The (1) xmlParserEntityCheck and (2) xmlParseAttValueComplex functions in parser.c in libxml2 2.9.3 do not properly keep track of the recursion depth, which allows context-dependent attackers to caus…
|
CWE-20
Improper Input Validation
|
CVE-2016-3705
|
2024-11-21 11:50 |
2016-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269218
|
7.5 |
HIGH
Network
|
fedoraproject debian xstream_project
|
fedora debian_linux xstream
|
Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) StandardStaxDriver, and (7) WstxDriver drivers in XStre…
|
CWE-200
Information Exposure
|
CVE-2016-3674
|
2024-11-21 11:50 |
2016-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269219
|
7.5 |
HIGH
Network
|
opensuse debian hp xmlsoft canonical redhat oracle
|
leap debian_linux icewall_file_manager icewall_federation_agent libxml2 ubuntu_linux enterprise_linux_desktop enterprise_linux_server_aus enterprise_linux_workstation enter…
|
The xmlStringGetNodeList function in tree.c in libxml2 2.9.3 and earlier, when used in recovery mode, allows context-dependent attackers to cause a denial of service (infinite recursion, stack consum…
|
CWE-674
Uncontrolled Recursion
|
CVE-2016-3627
|
2024-11-21 11:50 |
2016-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269220
|
5.5 |
MEDIUM
Local
|
oracle qemu canonical debian redhat citrix
|
vm_server qemu ubuntu_linux debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_tus enterprise_linux_server_aus<…
|
Integer overflow in the VGA module in QEMU allows local guest OS users to cause a denial of service (out-of-bounds read and QEMU process crash) by editing VGA registers in VBE mode.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2016-3712
|
2024-11-21 11:50 |
2016-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|