|
264711
|
5.9 |
MEDIUM
Network
|
powerdns debian
|
authoritative recursor debian_linux
|
An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 4.0.4, allowing an attacker in position of man-in-the-middle to alter the content of an AXFR because of insuf…
|
CWE-20
Improper Input Validation
|
CVE-2016-7074
|
2024-11-21 11:57 |
2018-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264712
|
5.9 |
MEDIUM
Network
|
powerdns debian
|
authoritative recursor debian_linux
|
An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 4.0.4, allowing an attacker in position of man-in-the-middle to alter the content of an AXFR because of insuf…
|
CWE-20
Improper Input Validation
|
CVE-2016-7073
|
2024-11-21 11:57 |
2018-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264713
|
8.0 |
HIGH
Adjacent
|
redhat
|
ansible_tower
|
A privilege escalation flaw was found in the Ansible Tower. When Tower before 3.0.3 deploys a PostgreSQL database, it incorrectly configures the trust level of postgres user. An attacker could use th…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-7070
|
2024-11-21 11:57 |
2018-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264714
|
7.5 |
HIGH
Network
|
powerdns
|
dnsdist
|
An issue has been found in dnsdist before 1.2.0 in the way EDNS0 OPT records are handled when parsing responses from a backend. When dnsdist is configured to add EDNS Client Subnet to a query, the re…
|
CWE-20
Improper Input Validation
|
CVE-2016-7069
|
2024-11-21 11:57 |
2018-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264715
|
7.5 |
HIGH
Network
|
powerdns debian
|
authoritative recursor debian_linux
|
An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 3.7.4 and 4.0.4, allowing a remote, unauthenticated attacker to cause an abnormal CPU usage load on the Power…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2016-7068
|
2024-11-21 11:57 |
2018-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264716
|
4.3 |
MEDIUM
Network
|
redhat
|
cloudforms cloudforms_management_engine
|
A flaw was found in the CloudForms API before 5.6.3.0, 5.7.3.1 and 5.8.1.2. A user with permissions to use the MiqReportResults capability within the API could potentially view data from other tenant…
|
CWE-200
Information Exposure
|
CVE-2016-7047
|
2024-11-21 11:57 |
2018-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264717
|
7.5 |
HIGH
Network
|
powerdns debian
|
authoritative debian_linux
|
An issue has been found in PowerDNS Authoritative Server before 3.4.11 and 4.0.2 allowing a remote, unauthenticated attacker to cause a denial of service by opening a large number of TCP connections …
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2016-7072
|
2024-11-21 11:57 |
2018-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264718
|
6.5 |
MEDIUM
Network
|
redhat
|
jboss_enterprise_application_platform
|
An information disclosure vulnerability was found in JBoss Enterprise Application Platform before 7.0.4. It was discovered that when configuring RBAC and marking information as sensitive, users with …
|
CWE-200
Information Exposure
|
CVE-2016-7061
|
2024-11-21 11:57 |
2018-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264719
|
5.5 |
MEDIUM
Local
|
openssl debian redhat canonical
|
openssl debian_linux enterprise_linux ubuntu_linux
|
A timing attack flaw was found in OpenSSL 1.0.1u and before that could allow a malicious user with local access to recover ECDSA P-256 private keys.
|
-
|
CVE-2016-7056
|
2024-11-21 11:57 |
2018-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264720
|
6.5 |
MEDIUM
Network
|
redhat
|
jboss_drools jboss_brms
|
Drools Workbench contains a path traversal vulnerability. The vulnerability allows a remote, authenticated attacker to bypass the directory restrictions and retrieve arbitrary files from the affected…
|
-
|
CVE-2016-7041
|
2024-11-21 11:57 |
2018-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|