|
258151
|
8.8 |
HIGH
Network
|
zlib opensuse debian canonical oracle redhat apple nodejs
|
zlib leap opensuse debian_linux ubuntu_linux mysql database_server jdk jre enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise…
|
inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
|
NVD-CWE-noinfo
|
CVE-2016-9840
|
2024-11-21 12:01 |
2017-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258152
|
6.5 |
MEDIUM
Network
|
ibm
|
qradar_security_information_and_event_manager
|
IBM QRadar 7.2 and 7.3 stores user credentials in plain in clear text which can be read by an authenticated user. IBM X-Force ID: 120207.
|
CWE-255
Credentials Management
|
CVE-2016-9750
|
2024-11-21 12:01 |
2017-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258153
|
4.3 |
MEDIUM
Network
|
ibm
|
rational_collaborative_lifecycle_management rational_quality_manager rational_team_concert rational_doors_next_generation rational_engineering_lifecycle_manager rational_rhapsody_desig…
|
IBM Jazz Foundation could allow an authenticated user to obtain sensitive information from stack traces. IBM X-Force ID: 119781,
|
CWE-200
Information Exposure
|
CVE-2016-9735
|
2024-11-21 12:01 |
2017-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258154
|
8.6 |
HIGH
Network
|
ibm
|
websphere_cast_iron_solution
|
IBM WebSphere Cast Iron Solution 7.0.0 and 7.5.0.0 is vulnerable to External Service Interaction attack, caused by improper validation of user-supplied input. A remote attacker could exploit this vul…
|
CWE-20
Improper Input Validation
|
CVE-2016-9692
|
2024-11-21 12:01 |
2017-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258155
|
8.6 |
HIGH
Network
|
ibm
|
websphere_cast_iron_solution
|
IBM WebSphere Cast Iron Solution 7.0.0 and 7.5.0.0 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could explo…
|
CWE-611
XXE
|
CVE-2016-9691
|
2024-11-21 12:01 |
2017-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258156
|
8.1 |
HIGH
Network
|
ibm
|
rational_rhapsody_design_manager rational_quality_manager rational_engineering_lifecycle_manager rational_software_architect_design_manager rational_collaborative_lifecycle_management …
|
IBM Jazz Foundation is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose…
|
CWE-611
XXE
|
CVE-2016-9707
|
2024-11-21 12:01 |
2017-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258157
|
4.7 |
MEDIUM
Network
|
brave
|
browser
|
Brave Browser iOS before 1.2.18 and Brave Browser Android 1.9.56 and earlier suffer from Full Address Bar Spoofing, allowing attackers to trick a victim by displaying a malicious page for legitimate …
|
CWE-79
Cross-site Scripting
|
CVE-2016-9473
|
2024-11-21 12:01 |
2017-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258158
|
5.4 |
MEDIUM
Network
|
revive-adserver
|
revive_adserver
|
Revive Adserver before 3.2.5 and 4.0.0 suffers from Reflected XSS. The Revive Adserver web installer scripts were vulnerable to a reflected XSS attack via the dbHost, dbUser, and possibly other param…
|
CWE-79
Cross-site Scripting
|
CVE-2016-9472
|
2024-11-21 12:01 |
2017-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258159
|
9.0 |
CRITICAL
Network
|
revive-adserver
|
revive_adserver
|
Revive Adserver before 3.2.5 and 4.0.0 suffers from Reflected File Download. `www/delivery/asyncspc.php` was vulnerable to the fairly new Reflected File Download (RFD) web attack vector that enables …
|
CWE-254
7PK - Security Features
|
CVE-2016-9470
|
2024-11-21 12:01 |
2017-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258160
|
5.3 |
MEDIUM
Network
|
owncloud nextcloud
|
owncloud nextcloud_server
|
Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from content spoofing in the dav app. The exception message displayed on the DAV endpoints contained partiall…
|
CWE-284
Improper Access Control
|
CVE-2016-9468
|
2024-11-21 12:01 |
2017-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|