|
258121
|
6.5 |
MEDIUM
Network
|
jasper_project canonical redhat
|
jasper ubuntu_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_tus enterprise_linux_server_aus enterprise_linux_server_…
|
JasPer before version 2.0.10 is vulnerable to a null pointer dereference was found in the decoded creation of JPEG 2000 image files. A specially crafted file could cause an application using JasPer t…
|
CWE-476
NULL Pointer Dereference
|
CVE-2016-9600
|
2024-11-21 12:01 |
2018-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258122
|
7.5 |
HIGH
Network
|
redhat
|
jboss_wildfly_application_server
|
Undertow in Red Hat wildfly before version 11.0.0.Beta1 is vulnerable to a resource exhaustion resulting in a denial of service. Undertow keeps a cache of seen HTTP headers in persistent connections.…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2016-9589
|
2024-11-21 12:01 |
2018-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258123
|
8.1 |
HIGH
Network
|
redhat
|
resteasy
|
JBoss RESTEasy before version 3.1.2 could be forced into parsing a request with YamlProvider, resulting in unmarshalling of potentially untrusted data which could allow an attacker to execute arbitra…
|
CWE-20
Improper Input Validation
|
CVE-2016-9606
|
2024-11-21 12:01 |
2018-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258124
|
5.5 |
MEDIUM
Local
|
jasper_project redhat debian
|
jasper enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_eus debian_linux
|
JasPer before version 2.0.12 is vulnerable to a use-after-free in the way it decodes certain JPEG 2000 image files resulting in a crash on the application using JasPer.
|
CWE-416
Use After Free
|
CVE-2016-9591
|
2024-11-21 12:01 |
2018-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258125
|
5.3 |
MEDIUM
Network
|
redhat
|
jboss_enterprise_application_platform
|
Red Hat JBoss EAP version 5 is vulnerable to a deserialization of untrusted data in the JMX endpoint when deserializes the credentials passed to it. An attacker could exploit this vulnerability resul…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2016-9585
|
2024-11-21 12:01 |
2018-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258126
|
9.8 |
CRITICAL
Network
|
carbonblack
|
carbon_black
|
A security design issue can allow an unprivileged user to interact with the Carbon Black Sensor and perform unauthorized actions.
|
CWE-254
7PK - Security Features
|
CVE-2016-9568
|
2024-11-21 12:01 |
2018-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258127
|
7.5 |
HIGH
Network
|
carbonblack
|
carbon_black
|
cb.exe in Carbon Black 5.1.1.60603 allows attackers to cause a denial of service (out-of-bounds read, invalid pointer dereference, and application crash) by leveraging access to the NetMon named pipe.
|
CWE-125 CWE-476
Out-of-bounds Read NULL Pointer Dereference
|
CVE-2016-9570
|
2024-11-21 12:01 |
2018-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258128
|
4.4 |
MEDIUM
Local
|
carbonblack
|
carbon_black
|
The cbstream.sys driver in Carbon Black 5.1.1.60603 allows local users with admin privileges to cause a denial of service (out-of-bounds read and system crash) via a large counter value in an 0x62430…
|
CWE-125
Out-of-bounds Read
|
CVE-2016-9569
|
2024-11-21 12:01 |
2018-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258129
|
4.2 |
MEDIUM
Network
|
ibm
|
qradar_security_information_and_event_manager
|
IBM QRadar 7.2 and 7.3 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. IBM X-Force ID: 119737.
|
CWE-284
Improper Access Control
|
CVE-2016-9722
|
2024-11-21 12:01 |
2018-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258130
|
5.4 |
MEDIUM
Network
|
ibm
|
curam_social_program_management
|
IBM Curam Social Program Management 6.0, 6.1, 6.2 and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the int…
|
CWE-79
Cross-site Scripting
|
CVE-2016-9732
|
2024-11-21 12:01 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|