|
266481
|
8.8 |
HIGH
Network
|
apache
|
jetspeed
|
Multiple SQL injection vulnerabilities in the User Manager service in Apache Jetspeed before 2.3.1 allow remote attackers to execute arbitrary SQL commands via the (1) role or (2) user parameter to s…
|
CWE-89
SQL Injection
|
CVE-2016-0710
|
2024-11-21 11:42 |
2016-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266482
|
7.2 |
HIGH
Network
|
apache
|
jetspeed
|
Directory traversal vulnerability in the Import/Export function in the Portal Site Manager in Apache Jetspeed before 2.3.1 allows remote authenticated administrators to write to arbitrary files, and …
|
CWE-22
Path Traversal
|
CVE-2016-0709
|
2024-11-21 11:42 |
2016-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266483
|
8.8 |
HIGH
Network
|
jenkins redhat
|
jenkins openshift
|
Multiple unspecified API endpoints in Jenkins before 1.650 and LTS before 1.642.2 allow remote authenticated users to execute arbitrary code via serialized data in an XML file, related to XStream and…
|
CWE-20
Improper Input Validation
|
CVE-2016-0792
|
2024-11-21 11:42 |
2016-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266484
|
9.8 |
CRITICAL
Network
|
redhat jenkins
|
openshift jenkins
|
Jenkins before 1.650 and LTS before 1.642.2 do not use a constant-time algorithm to verify CSRF tokens, which makes it easier for remote attackers to bypass a CSRF protection mechanism via a brute-fo…
|
CWE-200
Information Exposure
|
CVE-2016-0791
|
2024-11-21 11:42 |
2016-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266485
|
5.3 |
MEDIUM
Network
|
jenkins redhat
|
jenkins openshift
|
Jenkins before 1.650 and LTS before 1.642.2 do not use a constant-time algorithm to verify API tokens, which makes it easier for remote attackers to determine API tokens via a brute-force approach.
|
CWE-200 CWE-254
Information Exposure 7PK - Security Features
|
CVE-2016-0790
|
2024-11-21 11:42 |
2016-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266486
|
6.1 |
MEDIUM
Network
|
jenkins redhat
|
jenkins openshift
|
CRLF injection vulnerability in the CLI command documentation in Jenkins before 1.650 and LTS before 1.642.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitti…
|
CWE-20
Improper Input Validation
|
CVE-2016-0789
|
2024-11-21 11:42 |
2016-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266487
|
9.8 |
CRITICAL
Network
|
jenkins redhat
|
jenkins openshift
|
The remoting module in Jenkins before 1.650 and LTS before 1.642.2 allows remote attackers to execute arbitrary code by opening a JRMP listener.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-0788
|
2024-11-21 11:42 |
2016-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266488
|
9.8 |
CRITICAL
Network
|
samsung fedoraproject
|
x14j_firmware fedora
|
Multiple buffer overflows in (1) internal/XMLReader.cpp, (2) util/XMLURL.cpp, and (3) util/XMLUri.cpp in the XML Parser library in Apache Xerces-C before 3.1.3 allow remote attackers to cause a denia…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-0729
|
2024-11-21 11:42 |
2016-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266489
|
6.1 |
MEDIUM
Network
|
apache
|
activemq
|
The web-based administration console in Apache ActiveMQ 5.x before 5.13.2 does not send an X-Frame-Options HTTP header, which makes it easier for remote attackers to conduct clickjacking attacks via …
|
CWE-254
7PK - Security Features
|
CVE-2016-0734
|
2024-11-21 11:42 |
2016-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266490
|
8.8 |
HIGH
Network
|
emc
|
documentum_d2
|
EMC Documentum D2 before 4.6 lacks intended ACLs for configuration objects, which allows remote authenticated users to modify objects via unspecified vectors.
|
NVD-CWE-noinfo
|
CVE-2016-0888
|
2024-11-21 11:42 |
2016-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|