|
266331
|
5.5 |
MEDIUM
Local
|
linux redhat
|
linux_kernel enterprise_linux
|
The einj_error_inject function in drivers/acpi/apei/einj.c in the Linux kernel allows local users to simulate hardware errors and consequently cause a denial of service by leveraging failure to disab…
|
CWE-74
Injection
|
CVE-2016-3695
|
2024-11-21 11:50 |
2017-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266332
|
7.5 |
HIGH
Network
|
fedoraproject pulpproject
|
fedora pulp
|
Pulp before 2.8.5 uses bash's $RANDOM in an unsafe way to generate passwords.
|
CWE-255
Credentials Management
|
CVE-2016-3704
|
2024-11-21 11:50 |
2017-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266333
|
5.5 |
MEDIUM
Local
|
fedoraproject pulpproject
|
fedora pulp
|
The pulp-qpid-ssl-cfg script in Pulp before 2.8.5 allows local users to obtain the CA key.
|
CWE-200
Information Exposure
|
CVE-2016-3696
|
2024-11-21 11:50 |
2017-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266334
|
9.8 |
CRITICAL
Network
|
redhat
|
jboss_enterprise_application_platform
|
The PooledInvokerServlet in JBoss EAP 4.x and 5.x allows remote attackers to execute arbitrary code via a crafted serialized payload.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2016-3690
|
2024-11-21 11:50 |
2017-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266335
|
8.8 |
HIGH
Network
|
kallithea-scm
|
kallithea
|
Routes in Kallithea before 0.3.2 allows remote attackers to bypass the CSRF protection by using the GET HTTP request method.
|
CWE-352
Origin Validation Error
|
CVE-2016-3691
|
2024-11-21 11:50 |
2017-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266336
|
5.3 |
MEDIUM
Network
|
redhat
|
cloudforms_management_engine
|
Padding oracle flaw in CloudForms Management Engine (aka CFME) 5 allows remote attackers to obtain sensitive cleartext information.
|
CWE-200
Information Exposure
|
CVE-2016-3702
|
2024-11-21 11:50 |
2017-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266337
|
8.8 |
HIGH
Network
|
moodle
|
moodle
|
Cross-site request forgery (CSRF) vulnerability in markposts.php in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13 and earlier allows remote attackers to hijack t…
|
CWE-352
Origin Validation Error
|
CVE-2016-3734
|
2024-11-21 11:50 |
2017-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266338
|
4.3 |
MEDIUM
Network
|
moodle
|
moodle
|
The "restore teacher" feature in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlier allows remote authenticated users to overwrite the course idnumber.
|
CWE-284
Improper Access Control
|
CVE-2016-3733
|
2024-11-21 11:50 |
2017-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266339
|
4.3 |
MEDIUM
Network
|
moodle
|
moodle
|
The capability check to access other badges in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlier allows remote authenticated users to read the badges of…
|
CWE-200
Information Exposure
|
CVE-2016-3732
|
2024-11-21 11:50 |
2017-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266340
|
5.3 |
MEDIUM
Network
|
moodle
|
moodle
|
Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, and 2.8 through 2.8.11 allows remote attackers to obtain the names of hidden forums and forum discussions.
|
CWE-200
Information Exposure
|
CVE-2016-3731
|
2024-11-21 11:50 |
2017-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|