|
266041
|
9.8 |
CRITICAL
Network
|
solarwinds
|
virtualization_manager
|
The RMI service in SolarWinds Virtualization Manager 6.3.1 and earlier allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collec…
|
NVD-CWE-Other
|
CVE-2016-3642
|
2024-11-21 11:50 |
2016-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266042
|
5.3 |
MEDIUM
Network
|
f5
|
big-ip_access_policy_manager big-ip_edge_gateway
|
Open redirect vulnerability in F5 BIG-IP APM 11.2.1, 11.4.x, 11.5.x, and 11.6.x before 11.6.0 HF6 and Edge Gateway 11.2.1, when using multi-domain single sign-on (SSO), allows remote attackers to red…
|
NVD-CWE-Other
|
CVE-2016-3687
|
2024-11-21 11:50 |
2016-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266043
|
8.1 |
HIGH
Network
|
redhat libndp debian canonical
|
enterprise_linux_desktop enterprise_linux_server_aus enterprise_linux_workstation enterprise_linux_server enterprise_linux_hpc_node enterprise_linux_server_eus enterprise_linux_hpc_…
|
libndp before 1.6, as used in NetworkManager, does not properly validate the origin of Neighbor Discovery Protocol (NDP) messages, which allows remote attackers to conduct man-in-the-middle attacks o…
|
CWE-284
Improper Access Control
|
CVE-2016-3698
|
2024-11-21 11:50 |
2016-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266044
|
6.5 |
MEDIUM
Network
|
huawei
|
wear_app hilink_app
|
The Huawei Wear App application before 15.0.0.307 for Android does not validate SSL certificates, which allows local users to have unspecified impact via unknown vectors, aka HWPSIRT-2016-03008.
|
CWE-254 CWE-345
7PK - Security Features Insufficient Verification of Data Authenticity
|
CVE-2016-3677
|
2024-11-21 11:50 |
2016-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266045
|
6.1 |
MEDIUM
Network
|
liferay
|
liferay_portal
|
Cross-site scripting (XSS) vulnerability in users.jsp in the Profile Search functionality in Liferay before 7.0.0 CE RC1 allows remote attackers to inject arbitrary web script or HTML via the FirstNa…
|
CWE-79
Cross-site Scripting
|
CVE-2016-3670
|
2024-11-21 11:50 |
2016-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266046
|
9.8 |
CRITICAL
Network
|
fedoraproject fasterxml
|
fedora jackson-dataformat-xml
|
XML external entity (XXE) vulnerability in XmlMapper in the Data format extension for Jackson (aka jackson-dataformat-xml) allows attackers to have unspecified impact via unknown vectors.
|
NVD-CWE-noinfo
|
CVE-2016-3720
|
2024-11-21 11:50 |
2016-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266047
|
7.5 |
HIGH
Network
|
opensuse gnu
|
opensuse glibc
|
Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo.c in the GNU C Library (aka glibc or libc6) allows remote attackers to cause a denial of service (crash) via vecto…
|
CWE-20
Improper Input Validation
|
CVE-2016-3706
|
2024-11-21 11:50 |
2016-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266048
|
8.8 |
HIGH
Network
|
redhat
|
openshift
|
Red Hat OpenShift Enterprise 3.2 does not properly restrict access to STI builds, which allows remote authenticated users to access the Docker socket and gain privileges via vectors related to build-…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-3738
|
2024-11-21 11:50 |
2016-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266049
|
3.3 |
LOW
Local
|
redhat
|
openshift openshift_origin
|
HAproxy in Red Hat OpenShift Enterprise 3.2 and OpenShift Origin allows local users to obtain the internal IP address of a pod by reading the "OPENSHIFT_[namespace]_SERVERID" cookie.
|
CWE-200
Information Exposure
|
CVE-2016-3711
|
2024-11-21 11:50 |
2016-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266050
|
7.1 |
HIGH
Network
|
redhat
|
openshift
|
Red Hat OpenShift Enterprise 3.2, when multi-tenant SDN is enabled and a build is run in a namespace that would normally be isolated from pods in other namespaces, allows remote authenticated users t…
|
CWE-284
Improper Access Control
|
CVE-2016-3708
|
2024-11-21 11:50 |
2016-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|