|
265601
|
7.5 |
HIGH
Network
|
pulpproject
|
pulp
|
client/consumer/cli.py in Pulp before 2.8.3 writes consumer private keys to etc/pki/pulp/consumer/consumer-cert.pem as world-readable, which allows remote authenticated users to obtain the consumer p…
|
CWE-284
Improper Access Control
|
CVE-2016-3112
|
2024-11-21 11:49 |
2017-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265602
|
5.5 |
MEDIUM
Local
|
pulpproject
|
pulp
|
pulp.spec in the installation process for Pulp 2.8.3 generates the RSA key pairs used to validate messages between the pulp server and pulp consumers in a directory that is world-readable before late…
|
CWE-200
Information Exposure
|
CVE-2016-3111
|
2024-11-21 11:49 |
2017-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265603
|
7.1 |
HIGH
Local
|
pulpproject
|
pulp
|
The pulp-gen-nodes-certificate script in Pulp before 2.8.3 allows local users to leak the keys or write to arbitrary files via a symlink attack.
|
CWE-59
Link Following
|
CVE-2016-3108
|
2024-11-21 11:49 |
2017-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265604
|
5.5 |
MEDIUM
Local
|
pulpproject
|
pulp
|
The Node certificate in Pulp before 2.8.3 contains the private key, and is stored in a world-readable file in the "/etc/pki/pulp/nodes/" directory, which allows local users to gain access to sensitiv…
|
CWE-284
Improper Access Control
|
CVE-2016-3107
|
2024-11-21 11:49 |
2017-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265605
|
7.5 |
HIGH
Network
|
cloud_foundry
|
diego
|
Cloud Foundry Diego 0.1468.0 through 0.1470.0 allows remote attackers to cause a denial of service.
|
CWE-19
Data Processing Errors
|
CVE-2016-3091
|
2024-11-21 11:49 |
2017-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265606
|
4.3 |
MEDIUM
Network
|
ibm
|
security_access_manager_9.0_firmware
|
IBM Security Access Manager for Web 9.0.0 could allow an authenticated user to access some privileged functionality of the server. IBM X-Force ID: 114714.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-3051
|
2024-11-21 11:49 |
2017-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265607
|
6.5 |
MEDIUM
Network
|
ibm
|
security_access_manager_9.0_firmware
|
IBM Security Access Manager for Web 9.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 114462.
|
CWE-326
Inadequate Encryption Strength
|
CVE-2016-3019
|
2024-11-21 11:49 |
2017-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265608
|
6.5 |
MEDIUM
Network
|
redhat
|
ovirt-engine
|
The VersionMapper.fromKernelVersionString method in oVirt Engine allows remote authenticated users to cause a denial of service (process crash) for all VMs.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-3077
|
2024-11-21 11:49 |
2017-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265609
|
6.5 |
MEDIUM
Network
|
spice-gtk_project
|
spice-gtk
|
The spice-gtk widget allows remote authenticated users to obtain information from the host clipboard.
|
CWE-200
Information Exposure
|
CVE-2016-3066
|
2024-11-21 11:49 |
2017-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265610
|
7.5 |
HIGH
Network
|
apache
|
hive
|
Apache Hive (JDBC + HiveServer2) implements SSL for plain TCP and HTTP connections (it supports both transport modes). While validating the server's certificate during the connection setup, the clien…
|
CWE-295
Improper Certificate Validation
|
CVE-2016-3083
|
2024-11-21 11:49 |
2017-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|