|
265591
|
7.8 |
HIGH
Local
|
ibm
|
sametime
|
IBM Sametime Meeting Server 8.5.2 and 9.0 could store credentials of the Sametime Meetings user in the local cache of their browser which could be accessed by a local user. IBM X-Force ID: 113855.
|
CWE-255
Credentials Management
|
CVE-2016-2972
|
2024-11-21 11:49 |
2017-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265592
|
5.3 |
MEDIUM
Network
|
ibm
|
sametime
|
IBM Sametime Media Services 8.5.2 and 9.0 can disclose sensitive information in stack trace error logs that could aid an attacker in future attacks. IBM X-Force ID: 113898.
|
CWE-200
Information Exposure
|
CVE-2016-2971
|
2024-11-21 11:49 |
2017-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265593
|
4.3 |
MEDIUM
Network
|
ibm
|
sametime
|
IBM Sametime Meeting Server 8.5.2 and 9.0 may send replies that contain emails of people that should not be in these messages. IBM X-Force ID: 113850.
|
CWE-200
Information Exposure
|
CVE-2016-2969
|
2024-11-21 11:49 |
2017-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265594
|
6.5 |
MEDIUM
Network
|
ibm
|
sametime
|
IBM Sametime Meeting Server 8.5.2 and 9.0 is vulnerable to cross-site request forgery, caused by improper validation of user-supplied input. By persuading a user to visit a malicious link, a remote a…
|
CWE-352
Origin Validation Error
|
CVE-2016-2965
|
2024-11-21 11:49 |
2017-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265595
|
4.3 |
MEDIUM
Network
|
ibm
|
sametime
|
IBM Sametime Meeting Server 8.5.2 and 9.0 could allow a meeting room manager to remove the primary managers privileges. IBM X-Force ID: 113804.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-2959
|
2024-11-21 11:49 |
2017-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265596
|
4.3 |
MEDIUM
Network
|
ibm
|
sametime
|
IBM Sametime 8.5 and 9.0 meetings server may provide detailed information in an error message that may provide details about the application to possible attackers. IBM X-Force ID: 113851.
|
CWE-200
Information Exposure
|
CVE-2016-2970
|
2024-11-21 11:49 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265597
|
6.1 |
MEDIUM
Network
|
redhat
|
ovirt-engine
|
Cross-site scripting (XSS) vulnerability in ovirt-engine allows remote attackers to inject arbitrary web script or HTML.
|
CWE-79
Cross-site Scripting
|
CVE-2016-3113
|
2024-11-21 11:49 |
2017-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265598
|
7.5 |
HIGH
Network
|
netapp
|
data_ontap
|
NetApp Data ONTAP 8.1 and 8.2, when operating in 7-Mode, allows man-in-the-middle attackers to obtain sensitive information, gain privileges, or cause a denial of service via vectors related to the S…
|
CWE-254
7PK - Security Features
|
CVE-2016-3400
|
2024-11-21 11:49 |
2017-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265599
|
7.5 |
HIGH
Network
|
redhat
|
enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_hpc_node
|
mod_ns in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Workstation 7 allows remote attackers to force the u…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2016-3099
|
2024-11-21 11:49 |
2017-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265600
|
5.5 |
MEDIUM
Local
|
fedoraproject pulpproject
|
fedora pulp
|
server/bin/pulp-gen-ca-certificate in Pulp before 2.8.2 allows local users to read the generated private key.
|
CWE-200
Information Exposure
|
CVE-2016-3095
|
2024-11-21 11:49 |
2017-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|