|
264541
|
8.1 |
HIGH
Network
|
pivotal_software cloudfoundry
|
cloud_foundry cloud_foundry_uaa cloud_foundry_uaa_bosh
|
Cloud Foundry before 248; UAA 2.x before 2.7.4.12, 3.x before 3.6.5, and 3.7.x through 3.9.x before 3.9.3; and UAA bosh release (aka uaa-release) before 13.9 for UAA 3.6.5 and before 24 for UAA 3.9.3…
|
CWE-287
Improper Authentication
|
CVE-2016-6659
|
2024-11-21 11:56 |
2016-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264542
|
7.4 |
HIGH
Network
|
pivotal_software
|
cloud_foundry_ops_manager cloud_foundry_elastic_runtime
|
An open redirect vulnerability has been detected with some Pivotal Cloud Foundry Elastic Runtime components. Users of affected versions should apply the following mitigation: Upgrade PCF Elastic Runt…
|
CWE-601
Open Redirect
|
CVE-2016-6657
|
2024-11-21 11:56 |
2016-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264543
|
7.2 |
HIGH
Network
|
pivotal_software
|
greenplum
|
An issue was discovered in Pivotal Greenplum before 4.3.10.0. Creation of external tables using GPHDFS protocol has a vulnerability whereby arbitrary commands can be injected into the system. In orde…
|
CWE-77
Command Injection
|
CVE-2016-6656
|
2024-11-21 11:56 |
2016-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264544
|
6.1 |
MEDIUM
Network
|
open-xchange
|
ox_guard
|
An issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code which got injected to a mail with inline PGP signature gets executed when verifying the signature. Malicious script cod…
|
CWE-79
Cross-site Scripting
|
CVE-2016-6854
|
2024-11-21 11:56 |
2016-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264545
|
4.3 |
MEDIUM
Network
|
open-xchange
|
open-xchange_appsuite
|
An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. Users can provide local file paths to the RSS reader; the response and error code give hints about whether the provided file ex…
|
CWE-200
Information Exposure
|
CVE-2016-6852
|
2024-11-21 11:56 |
2016-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264546
|
5.5 |
MEDIUM
Local
|
open-xchange
|
open-xchange_appsuite
|
An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. API requests can be used to inject, generate and download executable files to the client ("Reflected File Download"). Malicious…
|
CWE-254
7PK - Security Features
|
CVE-2016-6848
|
2024-11-21 11:56 |
2016-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264547
|
6.1 |
MEDIUM
Network
|
open-xchange
|
ox_guard
|
An issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code and references to external websites can be injected to the names of PGP public keys. When requesting that key later on …
|
CWE-79
Cross-site Scripting
|
CVE-2016-6853
|
2024-11-21 11:56 |
2016-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264548
|
6.1 |
MEDIUM
Network
|
open-xchange
|
ox_guard
|
An issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code can be provided as parameter to the OX Guard guest reader web application. This allows cross-site scripting attacks aga…
|
CWE-79
Cross-site Scripting
|
CVE-2016-6851
|
2024-11-21 11:56 |
2016-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264549
|
6.1 |
MEDIUM
Network
|
open-xchange
|
open-xchange_appsuite
|
An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. SVG files can be used as profile pictures. In case their XML structure contains iframes and script code, that code may get exec…
|
CWE-79
Cross-site Scripting
|
CVE-2016-6850
|
2024-11-21 11:56 |
2016-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264550
|
6.1 |
MEDIUM
Network
|
open-xchange
|
open-xchange_appsuite
|
An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. SVG files can be used as mp3 album covers. In case their XML structure contains script code, that code may get executed when ca…
|
CWE-79
Cross-site Scripting
|
CVE-2016-6847
|
2024-11-21 11:56 |
2016-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|