|
267101
|
6.1 |
MEDIUM
Network
|
python debian fedoraproject
|
python debian_linux fedora
|
The CGIHandler class in Python before 2.7.12 does not protect against the HTTP_PROXY variable name clash in a CGI script, which could allow a remote attacker to redirect HTTP requests.
|
CWE-601
Open Redirect
|
CVE-2016-1000110
|
2024-11-21 11:42 |
2019-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267102
|
9.8 |
CRITICAL
Network
|
facebook
|
hhvm
|
hhvm before 3.12.11 has a use-after-free in the serialize_memoize_param() and ResourceBundle::__construct() functions.
|
CWE-416
Use After Free
|
CVE-2016-1000006
|
2024-11-21 11:42 |
2019-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267103
|
6.1 |
MEDIUM
Network
|
redhat fedoraproject
|
pagure fedora enterprise_linux
|
Pagure: XSS possible in file attachment endpoint
|
CWE-79
Cross-site Scripting
|
CVE-2016-1000037
|
2024-11-21 11:42 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267104
|
2.4 |
LOW
Physics
|
gnome redhat debian opensuse
|
gnome_display_manager enterprise_linux debian_linux leap
|
gdm3 3.14.2 and possibly later has an information leak before screen lock
|
CWE-200
Information Exposure
|
CVE-2016-1000002
|
2024-11-21 11:42 |
2019-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267105
|
5.9 |
MEDIUM
Network
|
pivotal_software
|
cloud_foundry_elastic_runtime
|
Pivotal Cloud Foundry Elastic Runtime version 1.4.0 through 1.4.5, 1.5.0 through 1.5.11 and 1.6.0 through 1.6.11 is vulnerable to a remote information disclosure. It was found that original mitigatio…
|
CWE-200
Information Exposure
|
CVE-2016-0715
|
2024-11-21 11:42 |
2018-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267106
|
8.8 |
HIGH
Network
|
infinispan
|
infinispan
|
The hotrod java client in infinispan before 9.1.0.Final automatically deserializes bytearray message contents in certain events. A malicious user could exploit this flaw by injecting a specially-craf…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2016-0750
|
2024-11-21 11:42 |
2018-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267107
|
9.8 |
CRITICAL
Network
|
suse pidgin
|
linux_enterprise_server pidgin
|
Pidgin version <2.11.0 contains a vulnerability in X.509 Certificates imports specifically due to improper check of return values from gnutls_x509_crt_init() and gnutls_x509_crt_import() that can res…
|
CWE-295
Improper Certificate Validation
|
CVE-2016-1000030
|
2024-11-21 11:42 |
2018-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267108
|
5.9 |
MEDIUM
Network
|
cloudfoundry
|
java_buildpack cf-release
|
Applications deployed to Cloud Foundry, versions v166 through v227, may be vulnerable to a remote disclosure of information, including, but not limited to environment variables and bound service deta…
|
CWE-200
Information Exposure
|
CVE-2016-0708
|
2024-11-21 11:42 |
2018-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267109
|
10.0 |
CRITICAL
Network
|
vmware
|
pivotal_software_mysql
|
MySQL for PCF tiles 1.7.x before 1.7.10 were discovered to log the AWS access key in plaintext. These credentials were logged to the Service Backup component logs, and not the system log, thus were n…
|
CWE-255 CWE-532
Credentials Management Inclusion of Sensitive Information in Log Files
|
CVE-2016-0898
|
2024-11-21 11:42 |
2018-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267110
|
9.8 |
CRITICAL
Network
|
kabona
|
webdatorcentral
|
A Plaintext Storage of a Password issue was discovered in Kabona AB WebDatorCentral (WDC) versions prior to Version 3.4.0. WDC stores password credentials in plaintext.
|
CWE-255
Credentials Management
|
CVE-2016-0872
|
2024-11-21 11:42 |
2017-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|