|
265091
|
5.3 |
MEDIUM
Network
|
miniprofiler
|
rack-mini-profiler
|
The rack-mini-profiler gem before 0.10.1 for Ruby allows remote attackers to obtain sensitive information about allocated strings and objects by leveraging incorrect ordering of security checks.
|
CWE-200
Information Exposure
|
CVE-2016-4442
|
2024-11-21 11:52 |
2017-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265092
|
7.8 |
HIGH
Local
|
apple
|
iphone_os mac_os_x tvos
|
Heap-based buffer overflow in IOHIDFamily in Apple iOS before 9.3.2, OS X before 10.11.5, and tvOS before 9.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-4650
|
2024-11-21 11:52 |
2017-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265093
|
3.3 |
LOW
Local
|
redhat
|
enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_hpc_node subscription-manager
|
The Subscription Manager package (aka subscription-manager) before 1.17.7-1 for Candlepin uses weak permissions (755) for subscription-manager cache directories, which allows local users to obtain se…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-4455
|
2024-11-21 11:52 |
2017-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265094
|
7.5 |
HIGH
Network
|
redhat
|
mod_cluster enterprise_linux
|
Stack-based buffer overflow in native/mod_manager/node.c in mod_cluster 1.2.9.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-4459
|
2024-11-21 11:52 |
2017-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265095
|
7.0 |
HIGH
Local
|
setroubleshoot_project redhat
|
setroubleshoot enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_hpc_node
|
The allow_execstack plugin for setroubleshoot allows local users to execute arbitrary commands by triggering an execstack SELinux denial with a crafted filename, related to the commands.getoutput fun…
|
CWE-77
Command Injection
|
CVE-2016-4446
|
2024-11-21 11:52 |
2017-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265096
|
7.0 |
HIGH
Local
|
setroubleshoot_project redhat
|
setroubleshoot enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_hpc_node
|
The fix_lookup_id function in sealert in setroubleshoot before 3.2.23 allows local users to execute arbitrary commands as root by triggering an SELinux denial with a crafted file name, related to exe…
|
CWE-77
Command Injection
|
CVE-2016-4445
|
2024-11-21 11:52 |
2017-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265097
|
7.0 |
HIGH
Local
|
setroubleshoot_project redhat
|
setroubleshoot enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_hpc_node
|
The allow_execmod plugin for setroubleshoot before 3.2.23 allows local users to execute arbitrary commands by triggering an execmod SELinux denial with a crafted binary filename, related to the comma…
|
CWE-77
Command Injection
|
CVE-2016-4444
|
2024-11-21 11:52 |
2017-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265098
|
7.5 |
HIGH
Network
|
xmlsoft debian oracle
|
libxml2 debian_linux solaris
|
The xmlBufAttrSerializeTxtContent function in xmlsave.c in libxml2 allows context-dependent attackers to cause a denial of service (out-of-bounds read and application crash) via a non-UTF-8 attribute…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2016-4483
|
2024-11-21 11:52 |
2017-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265099
|
8.8 |
HIGH
Network
|
pivotal_software cloudfoundry
|
cloud_foundry_elastic_runtime cloud_foundry cloud_foundry_uaa cloud_foundry_ops_manager cloud_foundry_uaa_bosh
|
SQL injection vulnerability in Pivotal Cloud Foundry (PCF) before 238; UAA 2.x before 2.7.4.4, 3.x before 3.3.0.2, and 3.4.x before 3.4.1; UAA BOSH before 11.2 and 12.x before 12.2; Elastic Runtime b…
|
CWE-89
SQL Injection
|
CVE-2016-4468
|
2024-11-21 11:52 |
2017-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265100
|
8.8 |
HIGH
Network
|
meteocontrol
|
weblog
|
A Cross-Site Request Forgery issue was discovered in Meteocontrol WEB'log Basic 100 all versions, Light all versions, Pro all versions, and Pro Unlimited all versions. There is no CSRF Token generate…
|
CWE-352
Origin Validation Error
|
CVE-2016-4504
|
2024-11-21 11:52 |
2017-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|