|
267111
|
8.8 |
HIGH
Network
|
cloudfoundry pivotal
|
cf-release user_account_and_authentication uaa-release elastic_runtime
|
The identity zones feature in Pivotal Cloud Foundry 208 through 229; UAA 2.0.0 through 2.7.3 and 3.0.0; UAA-Release 2 through 4, when configured with multiple identity zones; and Elastic Runtime 1.6.…
|
CWE-269
Improper Privilege Management
|
CVE-2016-0732
|
2024-11-21 11:42 |
2017-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267112
|
4.7 |
MEDIUM
Network
|
cloudfoundry
|
cf-release
|
Gorouter in Cloud Foundry cf-release v141 through v228 allows man-in-the-middle attackers to conduct cross-site scripting (XSS) attacks via vectors related to modified requests.
|
CWE-79
Cross-site Scripting
|
CVE-2016-0713
|
2024-11-21 11:42 |
2017-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267113
|
7.5 |
HIGH
Network
|
gnu
|
bash
|
The expansion of '\h' in the prompt string in bash 4.3 allows remote authenticated users to execute arbitrary code via shell metacharacters placed in 'hostname' of a machine.
|
CWE-78
OS Command
|
CVE-2016-0634
|
2024-11-21 11:42 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267114
|
5.9 |
MEDIUM
Network
|
apache canonical debian redhat netapp oracle
|
tomcat ubuntu_linux debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_aus jboss_enterprise_web_server enterpri…
|
The Realm implementations in Apache Tomcat versions 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not process the supplied password if the supplie…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2016-0762
|
2024-11-21 11:42 |
2017-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267115
|
7.5 |
HIGH
Network
|
apache
|
http_server
|
In Apache HTTP Server versions 2.4.0 to 2.4.23, mod_session_crypto was encrypting its data/cookie using the configured ciphers with possibly either CBC or ECB modes of operation (AES256-CBC by defaul…
|
CWE-310
Cryptographic Issues
|
CVE-2016-0736
|
2024-11-21 11:42 |
2017-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267116
|
6.2 |
MEDIUM
Local
|
redhat
|
networkmanager
|
Race condition in Network Manager before 1.0.12 as packaged in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux…
|
CWE-362
Race Condition
|
CVE-2016-0764
|
2024-11-21 11:42 |
2017-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267117
|
9.8 |
CRITICAL
Network
|
adobe
|
flash_player flash_player_extended_support_release flash_player_for_linux air air_sdk_\&_compiler air_sdk
|
Use after free vulnerability in Adobe Flash Player Desktop Runtime before 20.0.0.267, Adobe Flash Player Extended Support Release before 18.0.0.324, Adobe Flash Player for Google Chrome before 20.0.0…
|
CWE-416
Use After Free
|
CVE-2016-0959
|
2024-11-21 11:42 |
2017-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267118
|
7.5 |
HIGH
Network
|
postgresql
|
postgresql
|
PostgreSQL PL/Java after 9.0 does not honor access controls on large objects.
|
CWE-284
Improper Access Control
|
CVE-2016-0768
|
2024-11-21 11:42 |
2017-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267119
|
6.5 |
MEDIUM
Network
|
pl\/java_project
|
pl\/java
|
PostgreSQL PL/Java before 1.5.0 allows remote authenticated users with USAGE permission on the public schema to alter the public schema classpath.
|
CWE-269
Improper Privilege Management
|
CVE-2016-0767
|
2024-11-21 11:42 |
2017-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267120
|
9.8 |
CRITICAL
Network
|
nagios
|
nagios
|
The Fedora Nagios package uses "nagiosadmin" as the default password for the "nagiosadmin" administrator account, which makes it easier for remote attackers to obtain access by leveraging knowledge o…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2016-0726
|
2024-11-21 11:42 |
2017-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|