|
266181
|
8.8 |
HIGH
Network
|
redhat
|
cloudforms_management_engine
|
Red Hat CloudForms Management Engine 4.1 does not properly handle regular expressions passed to the expression engine via the JSON API and the web-based UI, which allows remote authenticated users to…
|
CWE-284
Improper Access Control
|
CVE-2016-7040
|
2024-11-21 11:57 |
2016-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266182
|
8.8 |
HIGH
Network
|
adobe
|
flash_player_desktop_runtime flash_player
|
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to execute arbitrary…
|
CWE-416
Use After Free
|
CVE-2016-7020
|
2024-11-21 11:57 |
2016-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266183
|
9.8 |
CRITICAL
Network
|
qemu debian
|
qemu debian_linux
|
Heap-based buffer overflow in the .receive callback of xlnx.xps-ethernetlite in QEMU (aka Quick Emulator) allows attackers to execute arbitrary code on the QEMU host via a large ethlite packet.
|
CWE-787
Out-of-bounds Write
|
CVE-2016-7161
|
2024-11-21 11:57 |
2016-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266184
|
7.5 |
HIGH
Network
|
opensuse haxx
|
leap libcurl
|
curl and libcurl before 7.50.2, when built with NSS and the libnsspem.so library is available at runtime, allow remote attackers to hijack the authentication of a TLS connection by leveraging reuse o…
|
CWE-287
Improper Authentication
|
CVE-2016-7141
|
2024-11-21 11:57 |
2016-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266185
|
5.9 |
MEDIUM
Network
|
redhat
|
jboss_enterprise_application_platform
|
Red Hat JBoss Enterprise Application Platform (EAP) 7, when operating as a reverse-proxy with default buffer sizes, allows remote attackers to cause a denial of service (CPU and disk consumption) via…
|
CWE-399
Resource Management Errors
|
CVE-2016-7046
|
2024-11-21 11:57 |
2016-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266186
|
6.5 |
MEDIUM
Network
|
libgd opensuse
|
libgd leap opensuse
|
The read_image_tga function in gd_tga.c in the GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted TGA image.
|
CWE-125
Out-of-bounds Read
|
CVE-2016-6905
|
2024-11-21 11:57 |
2016-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266187
|
9.8 |
CRITICAL
Network
|
adodb_project fedoraproject
|
adodb fedora
|
The qstr method in the PDO driver in the ADOdb Library for PHP before 5.x before 5.20.7 might allow remote attackers to conduct SQL injection attacks via vectors related to incorrect quoting.
|
CWE-89
SQL Injection
|
CVE-2016-7405
|
2024-11-21 11:57 |
2016-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266188
|
7.5 |
HIGH
Network
|
canonical djangoproject debian
|
ubuntu_linux django debian_linux
|
The cookie parsing code in Django before 1.8.15 and 1.9.x before 1.9.10, when used on a site with Google Analytics, allows remote attackers to bypass an intended CSRF protection mechanism by setting …
|
CWE-254
7PK - Security Features
|
CVE-2016-7401
|
2024-11-21 11:57 |
2016-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266189
|
7.5 |
HIGH
Network
|
redhat ceph_project
|
ceph_storage ceph
|
The RGW code in Ceph before 10.0.1, when authenticated-read ACL is applied to a bucket, allows remote attackers to list the bucket contents via a URL.
|
CWE-200 CWE-254
Information Exposure 7PK - Security Features
|
CVE-2016-7031
|
2024-11-21 11:57 |
2016-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266190
|
4.4 |
MEDIUM
Local
|
sophos
|
unified_threat_management_software
|
The Frontend component in Sophos UTM with firmware 9.405-5 and earlier allows local administrators to obtain sensitive password information by reading the "value" field of the SMTP user settings in t…
|
CWE-200
Information Exposure
|
CVE-2016-7397
|
2024-11-21 11:57 |
2016-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|