|
264961
|
4.9 |
MEDIUM
Network
|
ibm mariadb oracle debian canonical redhat
|
powerkvm mariadb mysql linux debian_linux ubuntu_linux enterprise_linux_desktop enterprise_linux_server_aus enterprise_linux_workstation enterprise_linux_server_tus ente…
|
Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and earlier and MariaDB before 5.5.50, 10.0.x before 10.0.26, and 10.1.x before 10.1.15 allows remote admi…
|
NVD-CWE-noinfo
|
CVE-2016-5440
|
2024-11-21 11:54 |
2016-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264962
|
4.9 |
MEDIUM
Network
|
oracle canonical
|
mysql ubuntu_linux
|
Unspecified vulnerability in Oracle MySQL 5.6.30 and earlier and 5.7.12 and earlier allows remote administrators to affect availability via vectors related to Server: Privileges.
|
NVD-CWE-noinfo
|
CVE-2016-5439
|
2024-11-21 11:54 |
2016-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264963
|
4.9 |
MEDIUM
Network
|
oracle
|
mysql
|
Unspecified vulnerability in Oracle MySQL 5.7.12 and earlier allows remote administrators to affect availability via vectors related to Server: Log.
|
NVD-CWE-noinfo
|
CVE-2016-5437
|
2024-11-21 11:54 |
2016-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264964
|
4.9 |
MEDIUM
Network
|
oracle
|
mysql
|
Unspecified vulnerability in Oracle MySQL 5.7.12 and earlier allows remote administrators to affect availability via vectors related to Server: InnoDB.
|
NVD-CWE-noinfo
|
CVE-2016-5436
|
2024-11-21 11:54 |
2016-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264965
|
5.9 |
MEDIUM
Network
|
misys
|
fusioncapital_opics_plus
|
Misys FusionCapital Opics Plus does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to obtain sensitive information via a crafted certificate.
|
NVD-CWE-Other
|
CVE-2016-5655
|
2024-11-21 11:54 |
2016-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264966
|
7.5 |
HIGH
Network
|
misys
|
fusioncapital_opics_plus
|
Misys FusionCapital Opics Plus allows remote authenticated users to gain privileges via a man-in-the-middle attack that modifies the xmlMessageOut parameter.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-5654
|
2024-11-21 11:54 |
2016-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264967
|
6.5 |
MEDIUM
Network
|
misys
|
fusioncapital_opics_plus
|
Multiple SQL injection vulnerabilities in Misys FusionCapital Opics Plus allow remote authenticated users to execute arbitrary SQL commands via the (1) ID or (2) Branch parameter.
|
CWE-89
SQL Injection
|
CVE-2016-5653
|
2024-11-21 11:54 |
2016-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264968
|
8.1 |
HIGH
Network
|
redhat hp oracle apache
|
enterprise_linux_desktop enterprise_linux_server_aus enterprise_linux_workstation enterprise_linux_server_tus enterprise_linux_server enterprise_linux_hpc_node enterprise_linux_serv…
|
Apache Tomcat 7.x through 7.0.70 and 8.x through 8.5.4, when the CGI Servlet is enabled, follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted cli…
|
CWE-284
Improper Access Control
|
CVE-2016-5388
|
2024-11-21 11:54 |
2016-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264969
|
8.1 |
HIGH
Network
|
apache hp oracle fedoraproject redhat debian canonical opensuse
|
http_server system_management_homepage enterprise_manager_ops_center solaris linux communications_user_data_repository fedora jboss_web_server jboss_enterprise_web_server j…
|
The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, wh…
|
NVD-CWE-noinfo
|
CVE-2016-5387
|
2024-11-21 11:54 |
2016-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264970
|
8.1 |
HIGH
Network
|
fedoraproject oracle redhat golang
|
fedora linux enterprise_linux_server_aus enterprise_linux_server enterprise_linux_server_eus go
|
The net/http package in Go through 1.6 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client da…
|
CWE-284
Improper Access Control
|
CVE-2016-5386
|
2024-11-21 11:54 |
2016-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|