|
266561
|
4.8 |
MEDIUM
Network
|
tenable
|
nessus
|
Tenable Nessus before 6.8 has a stored XSS issue that requires admin-level authentication to the Nessus UI, and would only potentially impact other admins. (Tenable ID 5198).
|
CWE-79
Cross-site Scripting
|
CVE-2016-1000028
|
2024-11-21 11:42 |
2019-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266562
|
6.1 |
MEDIUM
Network
|
erlang
|
erlang\/otp
|
inets in Erlang possibly 22.1 and earlier follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable…
|
CWE-601
Open Redirect
|
CVE-2016-1000107
|
2024-11-21 11:42 |
2019-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266563
|
6.1 |
MEDIUM
Network
|
yaws debian
|
yaws debian_linux
|
yaws before 2.0.4 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY …
|
CWE-601
Open Redirect
|
CVE-2016-1000108
|
2024-11-21 11:42 |
2019-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266564
|
8.8 |
HIGH
Network
|
apache opensuse
|
mod_fcgid leap opensuse
|
A security Bypass vulnerability exists in the FcgidPassHeader Proxy in mod_fcgid through 2016-07-07.
|
CWE-20
Improper Input Validation
|
CVE-2016-1000104
|
2024-11-21 11:42 |
2019-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266565
|
6.1 |
MEDIUM
Network
|
python debian fedoraproject
|
python debian_linux fedora
|
The CGIHandler class in Python before 2.7.12 does not protect against the HTTP_PROXY variable name clash in a CGI script, which could allow a remote attacker to redirect HTTP requests.
|
CWE-601
Open Redirect
|
CVE-2016-1000110
|
2024-11-21 11:42 |
2019-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266566
|
9.8 |
CRITICAL
Network
|
facebook
|
hhvm
|
hhvm before 3.12.11 has a use-after-free in the serialize_memoize_param() and ResourceBundle::__construct() functions.
|
CWE-416
Use After Free
|
CVE-2016-1000006
|
2024-11-21 11:42 |
2019-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266567
|
6.1 |
MEDIUM
Network
|
redhat fedoraproject
|
pagure fedora enterprise_linux
|
Pagure: XSS possible in file attachment endpoint
|
CWE-79
Cross-site Scripting
|
CVE-2016-1000037
|
2024-11-21 11:42 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266568
|
2.4 |
LOW
Physics
|
gnome redhat debian opensuse
|
gnome_display_manager enterprise_linux debian_linux leap
|
gdm3 3.14.2 and possibly later has an information leak before screen lock
|
CWE-200
Information Exposure
|
CVE-2016-1000002
|
2024-11-21 11:42 |
2019-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266569
|
5.9 |
MEDIUM
Network
|
pivotal_software
|
cloud_foundry_elastic_runtime
|
Pivotal Cloud Foundry Elastic Runtime version 1.4.0 through 1.4.5, 1.5.0 through 1.5.11 and 1.6.0 through 1.6.11 is vulnerable to a remote information disclosure. It was found that original mitigatio…
|
CWE-200
Information Exposure
|
CVE-2016-0715
|
2024-11-21 11:42 |
2018-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266570
|
8.8 |
HIGH
Network
|
infinispan
|
infinispan
|
The hotrod java client in infinispan before 9.1.0.Final automatically deserializes bytearray message contents in certain events. A malicious user could exploit this flaw by injecting a specially-craf…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2016-0750
|
2024-11-21 11:42 |
2018-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|