|
265851
|
9.8 |
CRITICAL
Network
|
lexmark
|
markvision_enterprise
|
Lexmark Markvision Enterprise (MVE) before 2.4.1 allows remote attackers to execute arbitrary commands by uploading files. (
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2016-6918
|
2024-11-21 11:57 |
2020-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265852
|
9.8 |
CRITICAL
Network
|
php
|
ext-http
|
A type confusion vulnerability in the merge_param() function of php_http_params.c in PHP's pecl-http extension 3.1.0beta2 (PHP 7) and earlier as well as 2.6.0beta2 (PHP 5) and earlier allows attacker…
|
CWE-704
Incorrect Type Conversion or Cast
|
CVE-2016-7398
|
2024-11-21 11:57 |
2019-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265853
|
9.8 |
CRITICAL
Network
|
openstack
|
magnum
|
OpenStack Magnum passes OpenStack credentials into the Heat templates creating its instances. While these should just be used for retrieving the instances' SSL certificates, they allow full API acces…
|
CWE-200
Information Exposure
|
CVE-2016-7404
|
2024-11-21 11:57 |
2019-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265854
|
9.8 |
CRITICAL
Network
|
redhat
|
kie-server
|
It has been reported that KIE server and Busitess Central before version 7.21.0.Final contain username and password as plaintext Java properties. Any app deployed on the same server would have access…
|
-
|
CVE-2016-7043
|
2024-11-21 11:57 |
2019-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265855
|
5.5 |
MEDIUM
Local
|
capstone-engine
|
capstone
|
Capstone 3.0.4 has an out-of-bounds vulnerability (SEGV caused by a read memory access) in X86_insn_reg_intel in arch/X86/X86Mapping.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2016-7151
|
2024-11-21 11:57 |
2019-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265856
|
7.8 |
HIGH
Local
|
redhat
|
jboss_enterprise_application_platform
|
It was found that the improper default permissions on /tmp/auth directory in JBoss Enterprise Application Platform before 7.1.0 can allow any local user to connect to CLI and allow the user to execut…
|
CWE-275
Permission Issues
|
CVE-2016-7066
|
2024-11-21 11:57 |
2018-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265857
|
5.9 |
MEDIUM
Network
|
powerdns debian
|
authoritative recursor debian_linux
|
An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 4.0.4, allowing an attacker in position of man-in-the-middle to alter the content of an AXFR because of insuf…
|
CWE-20
Improper Input Validation
|
CVE-2016-7074
|
2024-11-21 11:57 |
2018-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265858
|
5.9 |
MEDIUM
Network
|
powerdns debian
|
authoritative recursor debian_linux
|
An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 4.0.4, allowing an attacker in position of man-in-the-middle to alter the content of an AXFR because of insuf…
|
CWE-20
Improper Input Validation
|
CVE-2016-7073
|
2024-11-21 11:57 |
2018-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265859
|
8.0 |
HIGH
Adjacent
|
redhat
|
ansible_tower
|
A privilege escalation flaw was found in the Ansible Tower. When Tower before 3.0.3 deploys a PostgreSQL database, it incorrectly configures the trust level of postgres user. An attacker could use th…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-7070
|
2024-11-21 11:57 |
2018-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265860
|
7.5 |
HIGH
Network
|
powerdns
|
dnsdist
|
An issue has been found in dnsdist before 1.2.0 in the way EDNS0 OPT records are handled when parsing responses from a backend. When dnsdist is configured to add EDNS Client Subnet to a query, the re…
|
CWE-20
Improper Input Validation
|
CVE-2016-7069
|
2024-11-21 11:57 |
2018-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|