|
265851
|
6.3 |
MEDIUM
Network
|
freeipa
|
freeipa
|
Ipa versions 4.2.x, 4.3.x before 4.3.3 and 4.4.x before 4.4.3 did not properly check the user's permissions while modifying certificate profiles in IdM's certprofile-mod command. An authenticated, un…
|
CWE-285
Improper Authorization
|
CVE-2016-9575
|
2024-11-21 12:01 |
2018-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265852
|
6.5 |
MEDIUM
Network
|
jasper_project canonical redhat
|
jasper ubuntu_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_tus enterprise_linux_server_aus enterprise_linux_server_…
|
JasPer before version 2.0.10 is vulnerable to a null pointer dereference was found in the decoded creation of JPEG 2000 image files. A specially crafted file could cause an application using JasPer t…
|
CWE-476
NULL Pointer Dereference
|
CVE-2016-9600
|
2024-11-21 12:01 |
2018-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265853
|
7.5 |
HIGH
Network
|
redhat
|
jboss_wildfly_application_server
|
Undertow in Red Hat wildfly before version 11.0.0.Beta1 is vulnerable to a resource exhaustion resulting in a denial of service. Undertow keeps a cache of seen HTTP headers in persistent connections.…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2016-9589
|
2024-11-21 12:01 |
2018-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265854
|
8.1 |
HIGH
Network
|
redhat
|
resteasy
|
JBoss RESTEasy before version 3.1.2 could be forced into parsing a request with YamlProvider, resulting in unmarshalling of potentially untrusted data which could allow an attacker to execute arbitra…
|
CWE-20
Improper Input Validation
|
CVE-2016-9606
|
2024-11-21 12:01 |
2018-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265855
|
5.5 |
MEDIUM
Local
|
jasper_project redhat debian
|
jasper enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_eus debian_linux
|
JasPer before version 2.0.12 is vulnerable to a use-after-free in the way it decodes certain JPEG 2000 image files resulting in a crash on the application using JasPer.
|
CWE-416
Use After Free
|
CVE-2016-9591
|
2024-11-21 12:01 |
2018-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265856
|
5.3 |
MEDIUM
Network
|
redhat
|
jboss_enterprise_application_platform
|
Red Hat JBoss EAP version 5 is vulnerable to a deserialization of untrusted data in the JMX endpoint when deserializes the credentials passed to it. An attacker could exploit this vulnerability resul…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2016-9585
|
2024-11-21 12:01 |
2018-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265857
|
9.8 |
CRITICAL
Network
|
carbonblack
|
carbon_black
|
A security design issue can allow an unprivileged user to interact with the Carbon Black Sensor and perform unauthorized actions.
|
CWE-254
7PK - Security Features
|
CVE-2016-9568
|
2024-11-21 12:01 |
2018-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265858
|
7.5 |
HIGH
Network
|
carbonblack
|
carbon_black
|
cb.exe in Carbon Black 5.1.1.60603 allows attackers to cause a denial of service (out-of-bounds read, invalid pointer dereference, and application crash) by leveraging access to the NetMon named pipe.
|
CWE-125 CWE-476
Out-of-bounds Read NULL Pointer Dereference
|
CVE-2016-9570
|
2024-11-21 12:01 |
2018-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265859
|
4.4 |
MEDIUM
Local
|
carbonblack
|
carbon_black
|
The cbstream.sys driver in Carbon Black 5.1.1.60603 allows local users with admin privileges to cause a denial of service (out-of-bounds read and system crash) via a large counter value in an 0x62430…
|
CWE-125
Out-of-bounds Read
|
CVE-2016-9569
|
2024-11-21 12:01 |
2018-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265860
|
4.2 |
MEDIUM
Network
|
ibm
|
qradar_security_information_and_event_manager
|
IBM QRadar 7.2 and 7.3 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. IBM X-Force ID: 119737.
|
CWE-284
Improper Access Control
|
CVE-2016-9722
|
2024-11-21 12:01 |
2018-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|