|
257031
|
6.1 |
MEDIUM
Network
|
broadcom
|
advanced_secure_gateway symantec_proxysg
|
Symantec Advanced Secure Gateway (ASG) 6.6, ASG 6.7 prior to 6.7.2.1, ProxySG 6.5 prior to 6.5.10.6, ProxySG 6.6, and ProxySG 6.7 prior to 6.7.2.1 are susceptible to an open redirection vulnerability…
|
CWE-601
Open Redirect
|
CVE-2016-9099
|
2024-11-21 12:00 |
2017-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257032
|
7.2 |
HIGH
Network
|
broadcom
|
advanced_secure_gateway symantec_proxysg
|
The Symantec Advanced Secure Gateway (ASG) 6.6 prior to 6.6.5.8, ProxySG 6.5 prior 6.5.10.6, ProxySG 6.6 prior to 6.6.5.8, and ProxySG 6.7 prior to 6.7.1.2 management consoles do not, under certain c…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-9097
|
2024-11-21 12:00 |
2017-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257033
|
8.8 |
HIGH
Network
|
symantec
|
content_analysis mail_threat_defense
|
The Symantec Content Analysis (CA) 1.3, 2.x prior to 2.2.1.1, and Mail Threat Defense (MTD) 1.1 management consoles are susceptible to a cross-site request forging (CSRF) vulnerability. A remote atta…
|
CWE-352
Origin Validation Error
|
CVE-2016-9092
|
2024-11-21 12:00 |
2017-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257034
|
7.5 |
HIGH
Network
|
f5
|
big-ip_local_traffic_manager big-ip_application_acceleration_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_access_policy_manager big-ip_application_security_manager<…
|
In F5 BIG-IP 11.2.1, 11.4.0 through 11.6.1, and 12.0.0 through 12.1.2, an unauthenticated user with access to the control plane may be able to delete arbitrary files through an undisclosed mechanism.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-9250
|
2024-11-21 12:00 |
2017-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257035
|
6.1 |
MEDIUM
Network
|
f5
|
big-ip_access_policy_manager
|
In F5 BIG-IP APM 12.0.0 through 12.1.2, non-authenticated users may be able to inject JavaScript into a request that will then be rendered and executed in the context of the Administrative user when …
|
CWE-79
Cross-site Scripting
|
CVE-2016-9257
|
2024-11-21 12:00 |
2017-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257036
|
7.5 |
HIGH
Network
|
f5
|
big-ip_local_traffic_manager big-ip_application_acceleration_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_access_policy_manager big-ip_application_security_manager<…
|
In F5 BIG-IP 12.1.0 through 12.1.2, permissions enforced by iControl can lag behind the actual permissions assigned to a user if the role_map is not reloaded between the time the permissions are chan…
|
CWE-362
Race Condition
|
CVE-2016-9256
|
2024-11-21 12:00 |
2017-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257037
|
7.5 |
HIGH
Network
|
f5
|
big-ip_local_traffic_manager big-ip_application_acceleration_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_access_policy_manager big-ip_application_security_manager<…
|
In F5 BIG-IP 12.1.0 through 12.1.2, specific websocket traffic patterns may cause a disruption of service for virtual servers configured to use the websocket profile.
|
CWE-20
Improper Input Validation
|
CVE-2016-9253
|
2024-11-21 12:00 |
2017-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257038
|
8.8 |
HIGH
Network
|
f5
|
big-ip_local_traffic_manager big-ip_application_acceleration_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_access_policy_manager big-ip_application_security_manager<…
|
In F5 BIG-IP 12.0.0 through 12.1.2, an authenticated attacker may be able to cause an escalation of privileges through a crafted iControl REST connection.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-9251
|
2024-11-21 12:00 |
2017-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257039
|
5.5 |
MEDIUM
Local
|
ibm
|
tivoli_storage_manager
|
IBM Tivoli Storage Manager 5.5, 6.1-6.4, and 7.1 stores password information in a log file that could be read by a local user when a set password command is issued. IBM X-Force ID: 118472.
|
CWE-200
Information Exposure
|
CVE-2016-8916
|
2024-11-21 12:00 |
2017-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257040
|
5.9 |
MEDIUM
Network
|
ibm
|
bigfix_inventory
|
IBM BigFix Inventory 9.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 118851.
|
CWE-255
Credentials Management
|
CVE-2016-8962
|
2024-11-21 12:00 |
2017-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|