|
266041
|
5.3 |
MEDIUM
Network
|
openstack
|
nova
|
The libvirt driver in OpenStack Compute (Nova) before 2015.1.4 (kilo) and 12.0.x before 12.0.3 (liberty), when using raw storage and use_cow_images is set to false, allows remote authenticated users …
|
CWE-200
Information Exposure
|
CVE-2016-2140
|
2024-11-21 11:47 |
2016-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266042
|
8.1 |
HIGH
Network
|
saltstack opensuse
|
salt leap
|
Salt 2015.8.x before 2015.8.4 does not properly handle clear messages on the minion, which allows man-in-the-middle attackers to execute arbitrary code by inserting packets into the minion-master dat…
|
CWE-284
Improper Access Control
|
CVE-2016-1866
|
2024-11-21 11:47 |
2016-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266043
|
6.2 |
MEDIUM
Local
|
freebsd
|
freebsd
|
Integer signedness error in the amd64_set_ldt function in sys/amd64/amd64/sys_machdep.c in FreeBSD 9.3 before p39, 10.1 before p31, and 10.2 before p14 allows local users to cause a denial of service…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-1885
|
2024-11-21 11:47 |
2016-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266044
|
7.5 |
HIGH
Network
|
apache
|
jetspeed
|
The User Manager service in Apache Jetspeed before 2.3.1 does not properly restrict access using Jetspeed Security, which allows remote attackers to (1) add, (2) edit, or (3) delete users via the RES…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-2171
|
2024-11-21 11:47 |
2016-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266045
|
7.5 |
HIGH
Network
|
apache
|
openmeetings
|
The (1) FileService.importFileByInternalUserId and (2) FileService.importFile SOAP API methods in Apache OpenMeetings before 3.1.1 improperly use the Java URL class without checking the specified pro…
|
CWE-200
Information Exposure
|
CVE-2016-2164
|
2024-11-21 11:47 |
2016-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266046
|
6.1 |
MEDIUM
Network
|
apache
|
openmeetings
|
Cross-site scripting (XSS) vulnerability in Apache OpenMeetings before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the event description when creating an event.
|
CWE-79
Cross-site Scripting
|
CVE-2016-2163
|
2024-11-21 11:47 |
2016-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266047
|
7.3 |
HIGH
Network
|
debian rubyonrails
|
debian_linux ruby_on_rails rails
|
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to execute arbitrary Ruby code by leveraging an application's unrestricted use of t…
|
CWE-20
Improper Input Validation
|
CVE-2016-2098
|
2024-11-21 11:47 |
2016-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266048
|
5.3 |
MEDIUM
Network
|
rubyonrails
|
ruby_on_rails rails
|
Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.2 and 4.x before 4.1.14.2 allows remote attackers to read arbitrary files by leveraging an application's unrestricted u…
|
CWE-22
Path Traversal
|
CVE-2016-2097
|
2024-11-21 11:47 |
2016-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266049
|
7.5 |
HIGH
Network
|
nodejs fedoraproject
|
node.js fedora
|
Node.js 0.10.x before 0.10.42, 0.12.x before 0.12.10, 4.x before 4.3.0, and 5.x before 5.6.0 allow remote attackers to conduct HTTP request smuggling attacks via a crafted Content-Length HTTP header.
|
CWE-20
Improper Input Validation
|
CVE-2016-2086
|
2024-11-21 11:47 |
2016-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266050
|
9.8 |
CRITICAL
Network
|
hp
|
asset_manager asset_manager_cloudsystem_chargeback
|
HPE Asset Manager 9.40, 9.41, and 9.50 and Asset Manager CloudSystem Chargeback 9.40 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache C…
|
CWE-19
Data Processing Errors
|
CVE-2016-2000
|
2024-11-21 11:47 |
2016-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|