|
266281
|
7.5 |
HIGH
Network
|
cisco
|
firepower_management_center
|
SQL injection vulnerability in Cisco Firepower Management Center 4.10.3 through 5.4.0 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCur2548…
|
CWE-89
SQL Injection
|
CVE-2016-6419
|
2024-11-21 11:56 |
2016-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266282
|
9.8 |
CRITICAL
Network
|
emc dell
|
unisphere solutions_enabler emc_unisphere
|
The vApp Managers web application in EMC Unisphere for VMAX Virtual Appliance 8.x before 8.3.0 and Solutions Enabler Virtual Appliance 8.x before 8.3.0 allows remote attackers to execute arbitrary co…
|
CWE-20
Improper Input Validation
|
CVE-2016-6646
|
2024-11-21 11:56 |
2016-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266283
|
8.8 |
HIGH
Network
|
emc dell
|
unisphere solutions_enabler emc_unisphere
|
The vApp Managers web application in EMC Unisphere for VMAX Virtual Appliance 8.x before 8.3.0 and Solutions Enabler Virtual Appliance 8.x before 8.3.0 allows remote authenticated users to execute ar…
|
CWE-20
Improper Input Validation
|
CVE-2016-6645
|
2024-11-21 11:56 |
2016-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266284
|
5.4 |
MEDIUM
Adjacent
|
bb\&t
|
the_u
|
The U by BB&T app 1.5.4 and earlier for iOS does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information vi…
|
CWE-310
Cryptographic Issues
|
CVE-2016-6550
|
2024-11-21 11:56 |
2016-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266285
|
5.5 |
MEDIUM
Local
|
mongodb fedoraproject
|
mongodb fedora
|
The client in MongoDB uses world-readable permissions on .dbshell history files, which might allow local users to obtain sensitive information by reading these files.
|
CWE-200
Information Exposure
|
CVE-2016-6494
|
2024-11-21 11:56 |
2016-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266286
|
5.4 |
MEDIUM
Network
|
emc
|
vipr_srm
|
Cross-site scripting (XSS) vulnerability in EMC ViPR SRM before 4.0.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2016-6647
|
2024-11-21 11:56 |
2016-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266287
|
8.8 |
HIGH
Network
|
pivotal_software cloudfoundry
|
cloud_foundry_uaa cloud_foundry_elastic_runtime cloud_foundry_ops_manager cloud_foundry cloud_foundry_uaa_bosh
|
The UAA /oauth/token endpoint in Pivotal Cloud Foundry (PCF) before 243; UAA 2.x before 2.7.4.8, 3.x before 3.3.0.6, and 3.4.x before 3.4.5; UAA BOSH before 11.7 and 12.x before 12.6; Elastic Runtime…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-6651
|
2024-11-21 11:56 |
2016-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266288
|
9.6 |
CRITICAL
Network
|
pivotal_software cloudfoundry
|
cloud_foundry_elastic_runtime cloud_foundry_uaa cloud_foundry_ops_manager cloud_foundry cloud_foundry_uaa_bosh
|
Multiple cross-site request forgery (CSRF) vulnerabilities in Pivotal Cloud Foundry (PCF) before 242; UAA 2.x before 2.7.4.7, 3.x before 3.3.0.5, and 3.4.x before 3.4.4; UAA BOSH before 11.5 and 12.x…
|
CWE-352
Origin Validation Error
|
CVE-2016-6637
|
2024-11-21 11:56 |
2016-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266289
|
5.3 |
MEDIUM
Network
|
pivotal_software cloudfoundry
|
cloud_foundry_elastic_runtime cloud_foundry_uaa cloud_foundry_ops_manager cloud_foundry cloud_foundry_uaa_bosh
|
The OAuth authorization implementation in Pivotal Cloud Foundry (PCF) before 242; UAA 2.x before 2.7.4.7, 3.x before 3.3.0.5, and 3.4.x before 3.4.4; UAA BOSH before 11.5 and 12.x before 12.5; Elasti…
|
CWE-601
Open Redirect
|
CVE-2016-6636
|
2024-11-21 11:56 |
2016-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266290
|
6.5 |
MEDIUM
Network
|
huawei
|
fusioncompute
|
Huawei FusionCompute before V100R005C10CP7002 stores cleartext AES keys in a file, which allows remote authenticated users to obtain sensitive information via unspecified vectors.
|
CWE-200
Information Exposure
|
CVE-2016-6827
|
2024-11-21 11:56 |
2016-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|