|
265571
|
5.5 |
MEDIUM
Local
|
uclouvain
|
openjpeg
|
The color_esycc_to_rgb function in bin/common/color.c in OpenJPEG before 2.1.1 allows attackers to cause a denial of service (memory corruption) via a crafted jpeg 2000 file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-3182
|
2024-11-21 11:49 |
2020-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265572
|
6.5 |
MEDIUM
Network
|
cloudera
|
cloudera_manager
|
Cloudera Manager 5.x before 5.7.1 places Sensitive Data in cleartext Readable Files.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2016-3192
|
2024-11-21 11:49 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265573
|
6.5 |
MEDIUM
Network
|
cloudera
|
cdh
|
Cloudera CDH before 5.6.1 allows authorization bypass via direct internal API calls.
|
CWE-863
Incorrect Authorization
|
CVE-2016-3131
|
2024-11-21 11:49 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265574
|
5.9 |
MEDIUM
Network
|
ibm
|
rational_clearquest
|
IBM Rational ClearQuest 8.0 through 8.0.1.9 and 9.0 through 9.0.1.3 (CQ OSLC linkages, EmailRelay) fails to check the SSL certificate against the requested hostname. It is subject to a man-in-the-mid…
|
CWE-295
Improper Certificate Validation
|
CVE-2016-2922
|
2024-11-21 11:49 |
2018-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265575
|
8.1 |
HIGH
Network
|
ibm
|
tealeaf_customer_experience
|
IBM Tealeaf Customer Experience 8.7, 8.8, and 9.0.2 could allow a remote attacker under unusual circumstances to read operational data or TLS session state for any active sessions, cause denial of se…
|
CWE-20
Improper Input Validation
|
CVE-2016-2983
|
2024-11-21 11:49 |
2018-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265576
|
5.4 |
MEDIUM
Network
|
ibm
|
openpages_grc_platform
|
IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functio…
|
CWE-79
Cross-site Scripting
|
CVE-2016-3048
|
2024-11-21 11:49 |
2017-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265577
|
8.8 |
HIGH
Network
|
apache
|
struts
|
The TextParseUtil.translateVariables method in Apache Struts 2.x before 2.3.20 allows remote attackers to execute arbitrary code via a crafted OGNL expression with ANTLR tooling.
|
CWE-20
Improper Input Validation
|
CVE-2016-3090
|
2024-11-21 11:49 |
2017-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265578
|
5.4 |
MEDIUM
Network
|
ibm
|
openpages_grc_platform
|
IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser with…
|
CWE-79
Cross-site Scripting
|
CVE-2016-3049
|
2024-11-21 11:49 |
2017-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265579
|
9.8 |
CRITICAL
Network
|
apache
|
hadoop
|
The YARN NodeManager in Apache Hadoop 2.6.x before 2.6.5 and 2.7.x before 2.7.3 can leak the password for credential store provider used by the NodeManager to YARN Applications.
|
CWE-200
Information Exposure
|
CVE-2016-3086
|
2024-11-21 11:49 |
2017-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265580
|
6.3 |
MEDIUM
Network
|
ibm
|
sametime
|
The Sametime WebPlayer 8.5.2 and 9.0 is vulnerable to a script injection where a malicious site can inject their own script by exploiting a vulnerability in the way that the WebPlayer works. IBM X-Fo…
|
CWE-74
Injection
|
CVE-2016-2980
|
2024-11-21 11:49 |
2017-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|