|
258381
|
5.4 |
MEDIUM
Network
|
ibm
|
jazz_reporting_service
|
IBM Jazz Foundation Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the inten…
|
CWE-79
Cross-site Scripting
|
CVE-2016-9987
|
2024-11-21 12:02 |
2017-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258382
|
5.4 |
MEDIUM
Network
|
ibm
|
jazz_reporting_service
|
IBM Jazz Foundation Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the inten…
|
CWE-79
Cross-site Scripting
|
CVE-2016-9986
|
2024-11-21 12:02 |
2017-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258383
|
7.5 |
HIGH
Network
|
torproject
|
tor
|
Tor 0.3.x before 0.3.0.9 has a guard-selection algorithm that only considers the exit relay (not the exit relay's family), which might allow remote attackers to defeat intended anonymity properties b…
|
CWE-200
Information Exposure
|
CVE-2017-0377
|
2024-11-21 12:02 |
2017-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258384
|
5.9 |
MEDIUM
Network
|
ibm
|
qradar_security_information_and_event_manager
|
IBM QRadar 7.2 and 7.3 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerabi…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-9972
|
2024-11-21 12:02 |
2017-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258385
|
5.3 |
MEDIUM
Network
|
ibm
|
sterling_b2b_integrator
|
IBM Sterling B2B Integrator Standard Edition 5.2 could allow an authenticated user with special privileges to view files that they should not have access to. IBM X-Force ID: 120275.
|
CWE-200
Information Exposure
|
CVE-2016-9983
|
2024-11-21 12:02 |
2017-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258386
|
6.5 |
MEDIUM
Network
|
ibm
|
sterling_b2b_integrator
|
IBM Sterling B2B Integrator Standard Edition 5.2 could allow an authenticated user to obtain sensitive information such as account lists due to improper access control. IBM X-Force ID: 120274.
|
CWE-200
Information Exposure
|
CVE-2016-9982
|
2024-11-21 12:02 |
2017-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258387
|
8.1 |
HIGH
Network
|
microsoft
|
windows_xp windows_server_2003
|
A buffer overflow in Smart Card authentication code in gpkcsp.dll in Microsoft Windows XP through SP3 and Server 2003 through SP2 allows a remote attacker to execute arbitrary code on the target comp…
|
CWE-120
Classic Buffer Overflow
|
CVE-2017-0176
|
2024-11-21 12:02 |
2017-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258388
|
7.8 |
HIGH
Local
|
microsoft
|
windows_server_2012 windows_server_2008 windows_server_2016 windows_10 windows_8.1 windows_7
|
Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attack…
|
CWE-120
Classic Buffer Overflow
|
CVE-2017-0296
|
2024-11-21 12:02 |
2017-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258389
|
5.5 |
MEDIUM
Local
|
microsoft
|
windows_server_2016 windows_10
|
Microsoft Windows 10 1607 and 1703, and Windows Server 2016 allow an authenticated attacker to modify the C:\Users\DEFAULT folder structure, aka "Windows Default Folder Tampering Vulnerability".
|
NVD-CWE-noinfo
|
CVE-2017-0295
|
2024-11-21 12:02 |
2017-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258390
|
7.8 |
HIGH
Local
|
microsoft
|
windows_rt_8.1 windows_server_2012 windows_server_2016 windows_7 windows_10 windows_8.1 windows_server_2008
|
Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attack…
|
NVD-CWE-noinfo
|
CVE-2017-0294
|
2024-11-21 12:02 |
2017-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|