|
265861
|
8.8 |
HIGH
Network
|
vmware
|
vrealize_log_insight
|
Cross-site request forgery (CSRF) vulnerability in VMware vRealize Log Insight 2.x and 3.x before 3.3.2 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
|
CWE-352
Origin Validation Error
|
CVE-2016-2082
|
2024-11-21 11:47 |
2016-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265862
|
6.1 |
MEDIUM
Network
|
vmware
|
vrealize_log_insight
|
Cross-site scripting (XSS) vulnerability in VMware vRealize Log Insight 2.x and 3.x before 3.3.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2016-2081
|
2024-11-21 11:47 |
2016-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265863
|
5.9 |
MEDIUM
Network
|
vmware
|
nsx_edge vcloud_networking_and_security_edge
|
VMware NSX Edge 6.1 before 6.1.7 and 6.2 before 6.2.3 and vCNS Edge 5.5 before 5.5.4.3, when the SSL-VPN feature is configured, allow remote attackers to obtain sensitive information via unspecified …
|
CWE-200
Information Exposure
|
CVE-2016-2079
|
2024-11-21 11:47 |
2016-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265864
|
9.8 |
CRITICAL
Network
|
redhat
|
jgroups jboss_enterprise_application_platform
|
It was found that JGroups did not require necessary headers for encrypt and auth protocols from new nodes joining the cluster. An attacker could use this flaw to bypass security restrictions, and use…
|
NVD-CWE-noinfo
|
CVE-2016-2141
|
2024-11-21 11:47 |
2016-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265865
|
5.5 |
MEDIUM
Local
|
openssl oracle suse nodejs debian canonical
|
openssl solaris linux linux_enterprise node.js debian_linux ubuntu_linux
|
The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h does not properly ensure the use of constant-time operations, which makes it easier for local users to discover a DSA pr…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2016-2178
|
2024-11-21 11:47 |
2016-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265866
|
9.8 |
CRITICAL
Network
|
hp openssl oracle
|
icewall_sso icewall_mcrp icewall_sso_agent_option openssl solaris linux
|
OpenSSL through 1.0.2h incorrectly uses pointer arithmetic for heap-buffer boundary checks, which might allow remote attackers to cause a denial of service (integer overflow and application crash) or…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2016-2177
|
2024-11-21 11:47 |
2016-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265867
|
4.3 |
MEDIUM
Network
|
apple
|
safari iphone_os
|
The XSS auditor in WebKit, as used in Apple iOS before 9.3 and Safari before 9.1, does not properly handle redirects in block mode, which allows remote attackers to obtain sensitive information via a…
|
CWE-200
Information Exposure
|
CVE-2016-1864
|
2024-11-21 11:47 |
2016-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265868
|
3.3 |
LOW
Local
|
apple
|
mac_os_x
|
Intel Graphics Driver in Apple OS X before 10.11.5 allows attackers to obtain sensitive kernel memory-layout information via a crafted app, a different vulnerability than CVE-2016-1860.
|
CWE-200 CWE-254
Information Exposure 7PK - Security Features
|
CVE-2016-1862
|
2024-11-21 11:47 |
2016-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265869
|
7.8 |
HIGH
Local
|
apple
|
mac_os_x
|
The NVIDIA Graphics Drivers subsystem in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted ap…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-1861
|
2024-11-21 11:47 |
2016-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265870
|
3.3 |
LOW
Local
|
apple
|
mac_os_x
|
Intel Graphics Driver in Apple OS X before 10.11.5 allows attackers to obtain sensitive kernel memory-layout information via a crafted app, a different vulnerability than CVE-2016-1862.
|
CWE-200 CWE-254
Information Exposure 7PK - Security Features
|
CVE-2016-1860
|
2024-11-21 11:47 |
2016-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|