|
267151
|
5.4 |
MEDIUM
Network
|
ibm
|
algo_one
|
Cross-site scripting (XSS) vulnerability in IBM Algorithmics Algo One Algo Risk Application (ARA) 4.9.1 through 5.1.0 allows remote authenticated users to inject arbitrary web script or HTML via a cr…
|
CWE-79
Cross-site Scripting
|
CVE-2016-0390
|
2024-11-21 11:41 |
2016-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267152
|
4.3 |
MEDIUM
Network
|
ibm
|
cognos_tm1
|
IBM Cognos TM1 10.2.2 before FP5, when the host/pmhub/pm/admin AdminGroups setting is empty, allows remote authenticated users to cause a denial of service (configuration outage) via a non-empty valu…
|
CWE-20
Improper Input Validation
|
CVE-2016-0381
|
2024-11-21 11:41 |
2016-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267153
|
7.5 |
HIGH
Network
|
ibm
|
b2b_advanced_communications multi-enterprise_integration_gateway
|
IBM Multi-Enterprise Integration Gateway 1.0 through 1.0.0.1 and B2B Advanced Communications 1.0.0.2 through 1.0.0.4 do not require HTTPS, which might allow remote attackers to obtain sensitive infor…
|
CWE-200
Information Exposure
|
CVE-2016-0341
|
2024-11-21 11:41 |
2016-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267154
|
7.8 |
HIGH
Local
|
microsoft
|
word word_for_mac office office_compatibility_pack word_viewer
|
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, and Word Viewer allow remote …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-0198
|
2024-11-21 11:41 |
2016-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267155
|
8.8 |
HIGH
Network
|
microsoft
|
windows_rt_8.1 windows_server_2012 windows_7 windows_10 windows_8.1 windows_server_2008 windows_vista
|
The Imaging Component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 all…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-0195
|
2024-11-21 11:41 |
2016-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267156
|
5.3 |
MEDIUM
Network
|
microsoft
|
internet_explorer
|
Microsoft Internet Explorer 10 and 11 allows remote attackers to bypass file permissions and obtain sensitive information via a crafted web site, aka "Internet Explorer Information Disclosure Vulnera…
|
CWE-200
Information Exposure
|
CVE-2016-0194
|
2024-11-21 11:41 |
2016-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267157
|
7.5 |
HIGH
Network
|
microsoft
|
edge
|
The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-0193
|
2024-11-21 11:41 |
2016-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267158
|
7.5 |
HIGH
Network
|
microsoft
|
internet_explorer edge
|
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Br…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-0192
|
2024-11-21 11:41 |
2016-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267159
|
7.5 |
HIGH
Network
|
microsoft
|
edge
|
The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-0191
|
2024-11-21 11:41 |
2016-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267160
|
5.5 |
MEDIUM
Local
|
microsoft
|
windows_rt_8.1 windows_server_2012 windows_8.1
|
Volume Manager Driver in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT 8.1 does not properly check whether RemoteFX RDP USB disk accesses originate from the user who mounted …
|
CWE-200
Information Exposure
|
CVE-2016-0190
|
2024-11-21 11:41 |
2016-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|