|
256821
|
6.5 |
MEDIUM
Network
|
ikiwiki
|
ikiwiki
|
The fix for ikiwiki for CVE-2016-10026 was incomplete resulting in editing restriction bypass for git revert when using git versions older than 2.8.0. This has been fixed in 3.20161229.
|
CWE-284
Improper Access Control
|
CVE-2016-9645
|
2024-11-21 12:01 |
2018-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256822
|
5.3 |
MEDIUM
Network
|
ibm
|
cognos_analytics
|
IBM Predictive Solutions Foundation (IBM Cognos Analytics 11.0) reveals sensitive information in detailed error messages that could aid an attacker in further attacks against the system. IBM X-Force …
|
CWE-200
Information Exposure
|
CVE-2016-9711
|
2024-11-21 12:01 |
2018-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256823
|
9.8 |
CRITICAL
Network
|
pivotal_software
|
gemfire_for_pivotal_cloud_foundry
|
The GemFire broker for Cloud Foundry 1.6.x before 1.6.5 and 1.7.x before 1.7.1 has multiple API endpoints which do not require authentication and could be used to gain access to the cluster managed b…
|
CWE-287
Improper Authentication
|
CVE-2016-9880
|
2024-11-21 12:01 |
2018-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256824
|
6.3 |
MEDIUM
Network
|
freeipa
|
freeipa
|
Ipa versions 4.2.x, 4.3.x before 4.3.3 and 4.4.x before 4.4.3 did not properly check the user's permissions while modifying certificate profiles in IdM's certprofile-mod command. An authenticated, un…
|
CWE-285
Improper Authorization
|
CVE-2016-9575
|
2024-11-21 12:01 |
2018-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256825
|
6.5 |
MEDIUM
Network
|
jasper_project canonical redhat
|
jasper ubuntu_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_tus enterprise_linux_server_aus enterprise_linux_server_…
|
JasPer before version 2.0.10 is vulnerable to a null pointer dereference was found in the decoded creation of JPEG 2000 image files. A specially crafted file could cause an application using JasPer t…
|
CWE-476
NULL Pointer Dereference
|
CVE-2016-9600
|
2024-11-21 12:01 |
2018-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256826
|
7.5 |
HIGH
Network
|
redhat
|
jboss_wildfly_application_server
|
Undertow in Red Hat wildfly before version 11.0.0.Beta1 is vulnerable to a resource exhaustion resulting in a denial of service. Undertow keeps a cache of seen HTTP headers in persistent connections.…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2016-9589
|
2024-11-21 12:01 |
2018-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256827
|
8.1 |
HIGH
Network
|
redhat
|
resteasy
|
JBoss RESTEasy before version 3.1.2 could be forced into parsing a request with YamlProvider, resulting in unmarshalling of potentially untrusted data which could allow an attacker to execute arbitra…
|
CWE-20
Improper Input Validation
|
CVE-2016-9606
|
2024-11-21 12:01 |
2018-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256828
|
5.5 |
MEDIUM
Local
|
jasper_project redhat debian
|
jasper enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_eus debian_linux
|
JasPer before version 2.0.12 is vulnerable to a use-after-free in the way it decodes certain JPEG 2000 image files resulting in a crash on the application using JasPer.
|
CWE-416
Use After Free
|
CVE-2016-9591
|
2024-11-21 12:01 |
2018-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256829
|
5.3 |
MEDIUM
Network
|
redhat
|
jboss_enterprise_application_platform
|
Red Hat JBoss EAP version 5 is vulnerable to a deserialization of untrusted data in the JMX endpoint when deserializes the credentials passed to it. An attacker could exploit this vulnerability resul…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2016-9585
|
2024-11-21 12:01 |
2018-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256830
|
9.8 |
CRITICAL
Network
|
carbonblack
|
carbon_black
|
A security design issue can allow an unprivileged user to interact with the Carbon Black Sensor and perform unauthorized actions.
|
CWE-254
7PK - Security Features
|
CVE-2016-9568
|
2024-11-21 12:01 |
2018-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|