|
265771
|
6.8 |
MEDIUM
Network
|
ibm
|
security_privileged_identity_manager_virtual_appliance
|
IBM WebSphere Application Server (WAS) Liberty, as used in IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8, allows remote authenticated users to redirect users…
|
CWE-601
Open Redirect
|
CVE-2016-3040
|
2024-11-21 11:49 |
2016-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265772
|
8.8 |
HIGH
Network
|
ibm
|
connections
|
Cross-site request forgery (CSRF) vulnerability in IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to hijack the authentication of arbitrary …
|
CWE-352
Origin Validation Error
|
CVE-2016-3007
|
2024-11-21 11:49 |
2016-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265773
|
5.4 |
MEDIUM
Network
|
ibm
|
connections
|
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or H…
|
CWE-79
Cross-site Scripting
|
CVE-2016-3006
|
2024-11-21 11:49 |
2016-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265774
|
5.4 |
MEDIUM
Network
|
ibm
|
connections
|
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or H…
|
CWE-79
Cross-site Scripting
|
CVE-2016-3003
|
2024-11-21 11:49 |
2016-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265775
|
5.4 |
MEDIUM
Network
|
ibm
|
connections
|
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or H…
|
CWE-79
Cross-site Scripting
|
CVE-2016-3001
|
2024-11-21 11:49 |
2016-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265776
|
4.3 |
MEDIUM
Network
|
ibm
|
connections
|
The help service in IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to cause a denial of service (service degradation) via a crafted URL.
|
CWE-20
Improper Input Validation
|
CVE-2016-3000
|
2024-11-21 11:49 |
2016-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265777
|
6.5 |
MEDIUM
Network
|
ibm
|
connections
|
IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to obtain sensitive information via an unspecified brute-force attack.
|
CWE-200
Information Exposure
|
CVE-2016-2999
|
2024-11-21 11:49 |
2016-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265778
|
7.8 |
HIGH
Local
|
microsoft
|
excel excel_viewer office_compatibility_pack
|
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, and Excel Viewer allow remote attackers to execute arbitrary code via a crafted…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-3381
|
2024-11-21 11:49 |
2016-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265779
|
6.1 |
MEDIUM
Network
|
microsoft
|
exchange_server
|
Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2016 Cumulative Update 1 and 2 allows remote attackers to inject arbitrary web script or HTML via a meeting-invitation request, a…
|
CWE-79
Cross-site Scripting
|
CVE-2016-3379
|
2024-11-21 11:49 |
2016-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265780
|
7.4 |
HIGH
Network
|
microsoft
|
exchange_server
|
Open redirect vulnerability in Microsoft Exchange Server 2013 SP1, 2013 Cumulative Update 12, 2013 Cumulative Update 13, 2016 Cumulative Update 1, and 2016 Cumulative Update 2 allows remote attackers…
|
CWE-20
Improper Input Validation
|
CVE-2016-3378
|
2024-11-21 11:49 |
2016-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|