|
267401
|
6.5 |
MEDIUM
Adjacent
|
samba redhat
|
samba enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_tus enterprise_linux_server_aus enterprise_linux_server_eus gluster_st…
|
It was found that Samba before versions 4.5.3, 4.4.8, 4.3.13 always requested forwardable tickets when using Kerberos authentication. A service to which Samba authenticated using Kerberos could subse…
|
CWE-20
Improper Input Validation
|
CVE-2016-2125
|
2024-11-21 11:47 |
2018-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267402
|
5.5 |
MEDIUM
Local
|
redhat
|
openstack
|
A permissions flaw was found in redis, which sets weak permissions on certain files and directories that could potentially contain sensitive information. A local, unprivileged user could possibly use…
|
-
|
CVE-2016-2121
|
2024-11-21 11:47 |
2018-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267403
|
5.3 |
MEDIUM
Network
|
cloudfoundry
|
capi-release cf-release
|
Cloud Foundry Cloud Controller, capi-release versions prior to 1.0.0 and cf-release versions prior to v237, contain a business logic flaw. An application developer may create an application with a ro…
|
CWE-17
Code
|
CVE-2016-2169
|
2024-11-21 11:47 |
2018-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267404
|
6.5 |
MEDIUM
Network
|
netapp
|
data_ontap
|
NetApp Data ONTAP before 8.2.5 and 8.3.x before 8.3.2P12 allow remote authenticated users to cause a denial of service via vectors related to unsafe user input string handling.
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2016-1895
|
2024-11-21 11:47 |
2017-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267405
|
5.3 |
MEDIUM
Network
|
haproxy
|
haproxy
|
HAProxy statistics in openstack-tripleo-image-elements are non-authenticated over the network.
|
CWE-287
Improper Authentication
|
CVE-2016-2102
|
2024-11-21 11:47 |
2017-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267406
|
7.5 |
HIGH
Network
|
apache
|
http_server
|
In Apache HTTP Server versions 2.4.0 to 2.4.23, malicious input to mod_auth_digest can cause the server to crash, and each instance continues to crash even for subsequently valid requests.
|
CWE-20
Improper Input Validation
|
CVE-2016-2161
|
2024-11-21 11:47 |
2017-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267407
|
9.8 |
CRITICAL
Network
|
arubanetworks
|
clearpass
|
SQL injection vulnerability in ClearPass Policy Manager 6.5.x through 6.5.6 and 6.6.0.
|
CWE-89
SQL Injection
|
CVE-2016-2034
|
2024-11-21 11:47 |
2017-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267408
|
6.5 |
MEDIUM
Network
|
pivotal_software cloudfoundry
|
cloud_foundry_elastic_runtime cf-release
|
The Loggregator Traffic Controller endpoints in cf-release v231 and lower, Pivotal Elastic Runtime versions prior to 1.5.19 AND 1.6.x versions prior to 1.6.20 are not cleansing request URL paths when…
|
CWE-20
Improper Input Validation
|
CVE-2016-2165
|
2024-11-21 11:47 |
2017-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267409
|
7.8 |
HIGH
Local
|
lenovo
|
solution_center
|
The backend service process in Lenovo Solution Center (aka LSC) before 3.3.0002 allows local users to gain SYSTEM privileges via unspecified vectors.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-1876
|
2024-11-21 11:47 |
2017-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267410
|
6.5 |
MEDIUM
Network
|
samba
|
samba
|
Samba version 4.0.0 up to 4.5.2 is vulnerable to privilege elevation due to incorrect handling of the PAC (Privilege Attribute Certificate) checksum. A remote, authenticated, attacker can cause the w…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-2126
|
2024-11-21 11:47 |
2017-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|