|
266001
|
7.3 |
HIGH
Network
|
pivotal_software
|
cloud_foundry_elastic_runtime
|
Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.34 and 1.7.x before 1.7.12 places 169.254.0.0/16 in the all_open Application Security Group, which might allow remote attackers to bypass intend…
|
CWE-254
7PK - Security Features
|
CVE-2016-0896
|
2024-11-21 11:42 |
2016-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266002
|
9.8 |
CRITICAL
Network
|
pivotal_software
|
operations_manager
|
Pivotal Cloud Foundry (PCF) Ops Manager before 1.5.14 and 1.6.x before 1.6.9 uses the same cookie-encryption key across different customers' installations, which allows remote attackers to bypass ses…
|
CWE-287
Improper Authentication
|
CVE-2016-0883
|
2024-11-21 11:42 |
2016-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266003
|
6.5 |
MEDIUM
Network
|
python
|
python
|
The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an error when StartTLS fails, which might allow man-in-the-middle attackers to bypa…
|
CWE-693
Protection Mechanism Failure
|
CVE-2016-0772
|
2024-11-21 11:42 |
2016-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266004
|
8.1 |
HIGH
Network
|
emc
|
authentication_manager_prime
|
The Self-Service Portal in EMC RSA Authentication Manager (AM) Prime Self-Service 3.0 and 3.1 before 3.1 1915.42871 allows remote authenticated users to cause a denial of service (PIN change for an a…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-0915
|
2024-11-21 11:42 |
2016-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266005
|
8.8 |
HIGH
Network
|
apache
|
sentry
|
Multiple incomplete blacklist vulnerabilities in Apache Sentry before 1.7.0 allow remote authenticated users to execute arbitrary code via the (1) reflect, (2) reflect2, or (3) java_method Hive built…
|
CWE-284
Improper Access Control
|
CVE-2016-0760
|
2024-11-21 11:42 |
2016-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266006
|
5.4 |
MEDIUM
Network
|
apache
|
activemq
|
The administration web console in Apache ActiveMQ 5.x before 5.11.4, 5.12.x before 5.12.3, and 5.13.x before 5.13.2 allows remote authenticated users to conduct cross-site scripting (XSS) attacks and…
|
CWE-79
Cross-site Scripting
|
CVE-2016-0782
|
2024-11-21 11:42 |
2016-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266007
|
8.8 |
HIGH
Network
|
oracle
|
documaker insurance_policy_administration_j2ee insurance_calculation_engine insurance_rules_palette enterprise_manager_ops_center primavera_p6_enterprise_project_portfolio_management
|
Unspecified vulnerability in the Enterprise Manager Ops Center component in Oracle Enterprise Manager Grid Control 12.1.4, 12.2.2, and 12.3.2; the Oracle Health Sciences Information Manager component…
|
NVD-CWE-noinfo
|
CVE-2016-0635
|
2024-11-21 11:42 |
2016-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266008
|
8.8 |
HIGH
Network
|
emc
|
avamar
|
The web-restore interface in Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar through 7.1.2 and 7.2.x through 7.2.1 allows remote authenticated users to read or delete directori…
|
CWE-284
Improper Access Control
|
CVE-2016-0906
|
2024-11-21 11:42 |
2016-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266009
|
6.3 |
MEDIUM
Network
|
emc
|
rsa_archer_egrc
|
EMC RSA Archer GRC 5.5.x before 5.5.3.4 allows remote authenticated users to read the web.config.bak file, and obtain sensitive credential information, by modifying the IIS configuration to set a Con…
|
CWE-200
Information Exposure
|
CVE-2016-0899
|
2024-11-21 11:42 |
2016-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266010
|
7.8 |
HIGH
Local
|
redhat linux canonical
|
enterprise_linux_desktop enterprise_linux_server_aus enterprise_linux_workstation enterprise_linux_server enterprise_linux_hpc_node enterprise_linux_server_eus enterprise_linux_hpc_…
|
Integer overflow in lib/asn1_decoder.c in the Linux kernel before 4.6 allows local users to gain privileges via crafted ASN.1 data.
|
NVD-CWE-Other
|
CVE-2016-0758
|
2024-11-21 11:42 |
2016-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|