|
265081
|
7.8 |
HIGH
Local
|
apache
|
tika
|
Apache Tika before 1.13 does not properly initialize the XML parser or choose handlers, which might allow remote attackers to conduct XML External Entity (XXE) attacks via vectors involving (1) sprea…
|
CWE-611
XXE
|
CVE-2016-4434
|
2024-11-21 11:52 |
2017-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265082
|
8.8 |
HIGH
Network
|
apache
|
ofbiz
|
By manipulating the URL parameter externalLoginKey, a malicious, logged in user could pass valid Freemarker directives to the Template Engine that are reflected on the webpage; a specially crafted Fr…
|
CWE-20
Improper Input Validation
|
CVE-2016-4462
|
2024-11-21 11:52 |
2017-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265083
|
9.8 |
CRITICAL
Network
|
apache
|
pony_mail
|
Apache Pony Mail 0.6c through 0.8b allows remote attackers to bypass authentication.
|
CWE-287
Improper Authentication
|
CVE-2016-4460
|
2024-11-21 11:52 |
2017-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265084
|
7.5 |
HIGH
Network
|
gnu
|
gnutls
|
The "GNUTLS_KEYLOGFILE" environment variable in gnutls 3.4.12 allows remote attackers to overwrite and corrupt arbitrary files in the filesystem.
|
CWE-20
Improper Input Validation
|
CVE-2016-4456
|
2024-11-21 11:52 |
2017-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265085
|
8.4 |
HIGH
Network
|
hp
|
helion_openstack_glance
|
The glance-manage db in all versions of HPE Helion Openstack Glance allows deleted image ids to be reassigned, which allows remote authenticated users to cause other users to boot into a modified ima…
|
CWE-284
Improper Access Control
|
CVE-2016-4383
|
2024-11-21 11:52 |
2017-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265086
|
9.8 |
CRITICAL
Network
|
php suse
|
php linux_enterprise_software_development_kit linux_enterprise_module_for_web_scripting
|
/ext/phar/phar_object.c in PHP 7.0.7 and 5.6.x allows remote attackers to execute arbitrary code. NOTE: Introduced as part of an incomplete fix to CVE-2015-6833.
|
CWE-416
Use After Free
|
CVE-2016-4473
|
2024-11-21 11:52 |
2017-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265087
|
8.8 |
HIGH
Network
|
redhat
|
cloudforms
|
ManageIQ in CloudForms before 4.1 allows remote authenticated users to execute arbitrary code.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-4471
|
2024-11-21 11:52 |
2017-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265088
|
7.5 |
HIGH
Network
|
redhat
|
cloudforms_management_engine
|
CloudForms Management Engine before 5.8 includes a default SSL/TLS certificate.
|
CWE-310
Cryptographic Issues
|
CVE-2016-4457
|
2024-11-21 11:52 |
2017-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265089
|
9.0 |
CRITICAL
Network
|
pivotal
|
bosh_stemcell
|
An endpoint of the Agent running on the BOSH Director VM with stemcell versions prior to 3232.6 and 3146.13 may allow unauthenticated clients to read or write blobs or cause a denial of service attac…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-4435
|
2024-11-21 11:52 |
2017-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265090
|
5.9 |
MEDIUM
Network
|
apache
|
qpid_proton
|
The C client and C-based client bindings in the Apache Qpid Proton library before 0.13.1 on Windows do not properly verify that the server hostname matches a domain name in the subject's Common Name …
|
CWE-295
Improper Certificate Validation
|
CVE-2016-4467
|
2024-11-21 11:52 |
2017-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|