|
265441
|
7.5 |
HIGH
Network
|
ibm
|
qradar_security_information_and_event_manager
|
IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 executes unspecified processes at an incorrect privilege level, which makes it easier for remote authenticated users to obtain root access…
|
CWE-264 CWE-78
Permissions, Privileges, and Access Controls OS Command
|
CVE-2016-2876
|
2024-11-21 11:48 |
2016-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265442
|
3.1 |
LOW
Network
|
ibm
|
qradar_security_information_and_event_manager
|
IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 mishandles authorization, which allows remote authenticated users to obtain sensitive information via unspecified vectors.
|
CWE-284
Improper Access Control
|
CVE-2016-2874
|
2024-11-21 11:48 |
2016-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265443
|
8.8 |
HIGH
Network
|
ibm
|
qradar_security_information_and_event_manager
|
SQL injection vulnerability in IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2016-2873
|
2024-11-21 11:48 |
2016-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265444
|
7.8 |
HIGH
Local
|
ibm
|
qradar_security_information_and_event_manager
|
IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 uses cleartext storage for unspecified passwords, which allows local users to obtain sensitive information by reading a configuration file.
|
CWE-255
Credentials Management
|
CVE-2016-2871
|
2024-11-21 11:48 |
2016-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265445
|
5.4 |
MEDIUM
Network
|
ibm
|
qradar_security_information_and_event_manager
|
Multiple cross-site scripting (XSS) vulnerabilities in the UI in IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 allow remote authenticated users to inject arbitrary web script or HTML v…
|
CWE-79
Cross-site Scripting
|
CVE-2016-2869
|
2024-11-21 11:48 |
2016-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265446
|
5.4 |
MEDIUM
Network
|
ibm
|
rational_quality_manager rational_engineering_lifecycle_manager rational_team_concert rational_collaborative_lifecycle_management rational_rhapsody_design_manager rational_doors_next_g…
|
Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rationa…
|
CWE-79
Cross-site Scripting
|
CVE-2016-2864
|
2024-11-21 11:48 |
2016-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265447
|
7.5 |
HIGH
Network
|
isc
|
bind
|
ISC BIND 9.1.0 through 9.8.4-P2 and 9.9.0 through 9.9.2-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via malformed options data in an OPT resource recor…
|
CWE-20
Improper Input Validation
|
CVE-2016-2848
|
2024-11-21 11:48 |
2016-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265448
|
8.6 |
HIGH
Network
|
american_auto-matrix
|
aspect-matrix_building_automation_front-end_solutions_application aspect-nexus_building_automation_front-end_solutions_application
|
American Auto-Matrix Aspect-Nexus Building Automation Front-End Solutions application before 3.0.0 and Aspect-Matrix Building Automation Front-End Solutions application store passwords in cleartext, …
|
NVD-CWE-Other
|
CVE-2016-2308
|
2024-11-21 11:48 |
2016-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265449
|
7.5 |
HIGH
Network
|
american_auto-matrix
|
aspect-matrix_building_automation_front-end_solutions_application aspect-nexus_building_automation_front-end_solutions_application
|
American Auto-Matrix Aspect-Nexus Building Automation Front-End Solutions application before 3.0.0 and Aspect-Matrix Building Automation Front-End Solutions application allow remote attackers to read…
|
CWE-200
Information Exposure
|
CVE-2016-2307
|
2024-11-21 11:48 |
2016-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265450
|
7.5 |
HIGH
Network
|
oracle isc hp
|
linux vm_server bind hp-ux solaris
|
buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly construct responses, which allows remote attackers to cause a denial of service…
|
CWE-20
Improper Input Validation
|
CVE-2016-2776
|
2024-11-21 11:48 |
2016-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|