|
266081
|
6.1 |
MEDIUM
Network
|
apache
|
ofbiz
|
The default configuration of the Apache OFBiz framework offers a blog functionality. Different users are able to operate blogs which are related to specific parties. In the form field for the creatio…
|
CWE-79
Cross-site Scripting
|
CVE-2016-6800
|
2024-11-21 11:56 |
2017-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266082
|
7.5 |
HIGH
Network
|
apache
|
tomcat
|
The HTTP/2 header parser in Apache Tomcat 9.0.0.M1 to 9.0.0.M11 and 8.5.0 to 8.5.6 entered an infinite loop if a header was received that was larger than the available buffer. This made a denial of s…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-6817
|
2024-11-21 11:56 |
2017-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266083
|
7.5 |
HIGH
Network
|
apache debian netapp canonical oracle redhat
|
tomcat debian_linux snap_creator_framework oncommand_insight oncommand_shift ubuntu_linux tekelec_platform_distribution enterprise_linux_desktop enterprise_linux_workstation
|
A malicious web application running on Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 was able to bypass a configured SecurityManager via…
|
NVD-CWE-noinfo
|
CVE-2016-6796
|
2024-11-21 11:56 |
2017-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266084
|
7.5 |
HIGH
Network
|
apache oracle debian netapp canonical redhat
|
tomcat tekelec_platform_distribution debian_linux snap_creator_framework oncommand_insight oncommand_shift ubuntu_linux enterprise_linux_desktop enterprise_linux_workstation
|
The ResourceLinkFactory implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not limit web application access to global J…
|
CWE-863
Incorrect Authorization
|
CVE-2016-6797
|
2024-11-21 11:56 |
2017-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266085
|
6.1 |
MEDIUM
Network
|
apache
|
cxf
|
The HTTP transport module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 uses FormattedServiceListWriter to provide an HTML page which lists the names and absolute URL addresses of the availa…
|
CWE-79
Cross-site Scripting
|
CVE-2016-6812
|
2024-11-21 11:56 |
2017-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266086
|
5.3 |
MEDIUM
Network
|
apache debian redhat netapp canonical oracle
|
tomcat debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server jboss_enterprise_web_server enterprise_linux_eus enterprise_linux_server_tus …
|
When a SecurityManager is configured, a web application's ability to read system properties should be controlled by the SecurityManager. In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.R…
|
NVD-CWE-noinfo
|
CVE-2016-6794
|
2024-11-21 11:56 |
2017-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266087
|
9.8 |
CRITICAL
Network
|
apache
|
sling
|
In the XSS Protection API module before 1.0.12 in Apache Sling, the method XSS.getValidXML() uses an insecure SAX parser to validate the input string, which allows for XXE attacks in all scripts whic…
|
CWE-611
XXE
|
CVE-2016-6798
|
2024-11-21 11:56 |
2017-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266088
|
9.1 |
CRITICAL
Network
|
apache
|
wicket
|
The DiskFileItem class in Apache Wicket 6.x before 6.25.0 and 1.5.x before 1.5.17 allows remote attackers to cause a denial of service (infinite loop) and write to, move, and delete files with the pe…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2016-6793
|
2024-11-21 11:56 |
2017-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266089
|
9.8 |
CRITICAL
Network
|
cloudfoundry
|
cf-mysql-release cf-release
|
An issue was discovered in Cloud Foundry Foundation Cloud Foundry release versions prior to v245 and cf-mysql-release versions prior to v31. A command injection vulnerability was discovered in a comm…
|
CWE-77
Command Injection
|
CVE-2016-6655
|
2024-11-21 11:56 |
2017-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266090
|
7.5 |
HIGH
Network
|
bluecoat
|
proxysg cacheflow advanced_secure_gateway
|
Blue Coat Advanced Secure Gateway 6.6, CacheFlow 3.4, ProxySG 6.5 and 6.6 allows remote attackers to bypass blocked requests, user authentication, and payload scanning.
|
CWE-254
7PK - Security Features
|
CVE-2016-6594
|
2024-11-21 11:56 |
2017-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|