|
266111
|
8.8 |
HIGH
Network
|
cacti
|
cacti
|
SQL injection vulnerability in graph_view.php in Cacti 0.8.8.g allows remote authenticated users to execute arbitrary SQL commands via the host_group_data parameter.
|
CWE-89
SQL Injection
|
CVE-2016-3659
|
2024-11-21 11:50 |
2016-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266112
|
8.8 |
HIGH
Network
|
google canonical opensuse
|
v8 ubuntu_linux opensuse chrome
|
Multiple unspecified vulnerabilities in Google V8 before 4.9.385.33, as used in Google Chrome before 49.0.2623.108, allow attackers to cause a denial of service or possibly have other impact via unkn…
|
NVD-CWE-noinfo
|
CVE-2016-3679
|
2024-11-21 11:50 |
2016-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266113
|
5.4 |
MEDIUM
Network
|
thoughtbot
|
administrate
|
Cross-site request forgery (CSRF) vulnerability in administrate 0.1.4 and earlier allows remote attackers to hijack the user's OAuth autorization code.
|
CWE-352
Origin Validation Error
|
CVE-2016-3098
|
2024-11-21 11:49 |
2022-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266114
|
5.5 |
MEDIUM
Local
|
uclouvain
|
openjpeg
|
The color_esycc_to_rgb function in bin/common/color.c in OpenJPEG before 2.1.1 allows attackers to cause a denial of service (memory corruption) via a crafted jpeg 2000 file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-3182
|
2024-11-21 11:49 |
2020-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266115
|
6.5 |
MEDIUM
Network
|
cloudera
|
cloudera_manager
|
Cloudera Manager 5.x before 5.7.1 places Sensitive Data in cleartext Readable Files.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2016-3192
|
2024-11-21 11:49 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266116
|
6.5 |
MEDIUM
Network
|
cloudera
|
cdh
|
Cloudera CDH before 5.6.1 allows authorization bypass via direct internal API calls.
|
CWE-863
Incorrect Authorization
|
CVE-2016-3131
|
2024-11-21 11:49 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266117
|
5.9 |
MEDIUM
Network
|
ibm
|
rational_clearquest
|
IBM Rational ClearQuest 8.0 through 8.0.1.9 and 9.0 through 9.0.1.3 (CQ OSLC linkages, EmailRelay) fails to check the SSL certificate against the requested hostname. It is subject to a man-in-the-mid…
|
CWE-295
Improper Certificate Validation
|
CVE-2016-2922
|
2024-11-21 11:49 |
2018-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266118
|
8.1 |
HIGH
Network
|
ibm
|
tealeaf_customer_experience
|
IBM Tealeaf Customer Experience 8.7, 8.8, and 9.0.2 could allow a remote attacker under unusual circumstances to read operational data or TLS session state for any active sessions, cause denial of se…
|
CWE-20
Improper Input Validation
|
CVE-2016-2983
|
2024-11-21 11:49 |
2018-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266119
|
5.4 |
MEDIUM
Network
|
ibm
|
openpages_grc_platform
|
IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functio…
|
CWE-79
Cross-site Scripting
|
CVE-2016-3048
|
2024-11-21 11:49 |
2017-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266120
|
8.8 |
HIGH
Network
|
apache
|
struts
|
The TextParseUtil.translateVariables method in Apache Struts 2.x before 2.3.20 allows remote attackers to execute arbitrary code via a crafted OGNL expression with ANTLR tooling.
|
CWE-20
Improper Input Validation
|
CVE-2016-3090
|
2024-11-21 11:49 |
2017-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|