|
264751
|
5.4 |
MEDIUM
Adjacent
|
bb\&t
|
the_u
|
The U by BB&T app 1.5.4 and earlier for iOS does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information vi…
|
CWE-310
Cryptographic Issues
|
CVE-2016-6550
|
2024-11-21 11:56 |
2016-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264752
|
5.5 |
MEDIUM
Local
|
mongodb fedoraproject
|
mongodb fedora
|
The client in MongoDB uses world-readable permissions on .dbshell history files, which might allow local users to obtain sensitive information by reading these files.
|
CWE-200
Information Exposure
|
CVE-2016-6494
|
2024-11-21 11:56 |
2016-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264753
|
5.4 |
MEDIUM
Network
|
emc
|
vipr_srm
|
Cross-site scripting (XSS) vulnerability in EMC ViPR SRM before 4.0.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2016-6647
|
2024-11-21 11:56 |
2016-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264754
|
8.8 |
HIGH
Network
|
pivotal_software cloudfoundry
|
cloud_foundry_uaa cloud_foundry_elastic_runtime cloud_foundry_ops_manager cloud_foundry cloud_foundry_uaa_bosh
|
The UAA /oauth/token endpoint in Pivotal Cloud Foundry (PCF) before 243; UAA 2.x before 2.7.4.8, 3.x before 3.3.0.6, and 3.4.x before 3.4.5; UAA BOSH before 11.7 and 12.x before 12.6; Elastic Runtime…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-6651
|
2024-11-21 11:56 |
2016-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264755
|
9.6 |
CRITICAL
Network
|
pivotal_software cloudfoundry
|
cloud_foundry_elastic_runtime cloud_foundry_uaa cloud_foundry_ops_manager cloud_foundry cloud_foundry_uaa_bosh
|
Multiple cross-site request forgery (CSRF) vulnerabilities in Pivotal Cloud Foundry (PCF) before 242; UAA 2.x before 2.7.4.7, 3.x before 3.3.0.5, and 3.4.x before 3.4.4; UAA BOSH before 11.5 and 12.x…
|
CWE-352
Origin Validation Error
|
CVE-2016-6637
|
2024-11-21 11:56 |
2016-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264756
|
5.3 |
MEDIUM
Network
|
pivotal_software cloudfoundry
|
cloud_foundry_elastic_runtime cloud_foundry_uaa cloud_foundry_ops_manager cloud_foundry cloud_foundry_uaa_bosh
|
The OAuth authorization implementation in Pivotal Cloud Foundry (PCF) before 242; UAA 2.x before 2.7.4.7, 3.x before 3.3.0.5, and 3.4.x before 3.4.4; UAA BOSH before 11.5 and 12.x before 12.5; Elasti…
|
CWE-601
Open Redirect
|
CVE-2016-6636
|
2024-11-21 11:56 |
2016-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264757
|
6.5 |
MEDIUM
Network
|
huawei
|
fusioncompute
|
Huawei FusionCompute before V100R005C10CP7002 stores cleartext AES keys in a file, which allows remote authenticated users to obtain sensitive information via unspecified vectors.
|
CWE-200
Information Exposure
|
CVE-2016-6827
|
2024-11-21 11:56 |
2016-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264758
|
6.5 |
MEDIUM
Network
|
huawei
|
anyoffice_secureapp
|
Huawei AnyMail before 2.6.0301.0060 allows remote attackers to cause a denial of service (application crash) via a crafted compressed email attachment.
|
CWE-284
Improper Access Control
|
CVE-2016-6826
|
2024-11-21 11:56 |
2016-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264759
|
7.5 |
HIGH
Network
|
huawei
|
s5300_firmware s12700_firmware s6300_firmware s7700_firmware s5700_firmware s6700_firmware s9700_firmware s9300_firmware
|
Memory leak in Huawei S9300, S5300, S5700, S6700, S7700, S9700, and S12700 devices allows remote attackers to cause a denial of service (memory consumption and restart) via a large number of malforme…
|
CWE-399
Resource Management Errors
|
CVE-2016-6518
|
2024-11-21 11:56 |
2016-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264760
|
6.1 |
MEDIUM
Network
|
huawei
|
oceanstor_ism
|
Cross-site scripting (XSS) vulnerability in the management interface in Huawei OceanStor ISM before V200R001C04SPC200 allows remote attackers to inject arbitrary web script or HTML via the loginName …
|
CWE-79
Cross-site Scripting
|
CVE-2016-6840
|
2024-11-21 11:56 |
2016-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|