|
265311
|
6.1 |
MEDIUM
Network
|
novell
|
groupwise
|
Multiple cross-site scripting (XSS) vulnerabilities in the administrator console in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 allow remote attackers to inject arbitrary web script or…
|
CWE-79
Cross-site Scripting
|
CVE-2016-5760
|
2024-11-21 11:54 |
2017-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265312
|
7.5 |
HIGH
Network
|
redhat
|
openshift
|
Red Hat OpenShift Enterprise 2 does not include the HTTPOnly flag in a Set-Cookie header for the GEARID cookie, which makes it easier for remote attackers to obtain potentially sensitive information …
|
CWE-200
Information Exposure
|
CVE-2016-5409
|
2024-11-21 11:54 |
2017-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265313
|
5.5 |
MEDIUM
Local
|
firewalld redhat
|
firewalld enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_hpc_node
|
firewalld.py in firewalld before 0.4.3.3 allows local users to bypass authentication and modify firewall configurations via the (1) addPassthrough, (2) removePassthrough, (3) addEntry, (4) removeEntr…
|
CWE-287
Improper Authentication
|
CVE-2016-5410
|
2024-11-21 11:54 |
2017-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265314
|
7.5 |
HIGH
Network
|
apache
|
traffic_server
|
Apache Traffic Server 6.0.0 to 6.2.0 are affected by an HPACK Bomb Attack.
|
CWE-399
Resource Management Errors
|
CVE-2016-5396
|
2024-11-21 11:54 |
2017-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265315
|
6.5 |
MEDIUM
Network
|
symantec
|
messaging_gateway
|
Directory traversal vulnerability in the charting component in Symantec Messaging Gateway before 10.6.2 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the sn paramete…
|
CWE-22
Path Traversal
|
CVE-2016-5312
|
2024-11-21 11:54 |
2017-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265316
|
5.5 |
MEDIUM
Local
|
symantec broadcom
|
protection_engine protection_for_sharepoint_servers mail_security_for_microsoft_exchange messaging_gateway mail_security_for_domino endpoint_protection endpoint_protection_for_small…
|
The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP); Symantec Email Security.Cloud; Symantec Data Center Security: Server; Symantec …
|
CWE-787
Out-of-bounds Write
|
CVE-2016-5310
|
2024-11-21 11:54 |
2017-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265317
|
5.5 |
MEDIUM
Local
|
symantec broadcom
|
protection_engine protection_for_sharepoint_servers mail_security_for_microsoft_exchange messaging_gateway mail_security_for_domino endpoint_protection endpoint_protection_for_small…
|
The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP); Symantec Email Security.Cloud; Symantec Data Center Security: Server; Symantec …
|
CWE-125
Out-of-bounds Read
|
CVE-2016-5309
|
2024-11-21 11:54 |
2017-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265318
|
8.8 |
HIGH
Network
|
symantec
|
web_gateway
|
Symantec Web Gateway (SWG) before 5.2.5 allows remote authenticated users to execute arbitrary OS commands.
|
CWE-78
OS Command
|
CVE-2016-5313
|
2024-11-21 11:54 |
2017-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265319
|
5.5 |
MEDIUM
Local
|
libtiff debian
|
libtiff debian_linux
|
The setByteArray function in tif_dir.c in libtiff 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tiff image.
|
CWE-125
Out-of-bounds Read
|
CVE-2016-5322
|
2024-11-21 11:54 |
2017-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265320
|
6.1 |
MEDIUM
Network
|
smartbear
|
swagger-ui
|
Swagger-UI before 2.2.1 has XSS via the Default field in the Definitions section.
|
CWE-79
Cross-site Scripting
|
CVE-2016-5682
|
2024-11-21 11:54 |
2017-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|