|
266051
|
5.3 |
MEDIUM
Network
|
redhat
|
openshift
|
Red Hat OpenShift Enterprise 3.2 and 3.1 do not properly validate the origin of a request when anonymous access is granted to a service/proxy or pod/proxy API for a specific pod, which allows remote …
|
CWE-284
Improper Access Control
|
CVE-2016-3703
|
2024-11-21 11:50 |
2016-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266052
|
7.5 |
HIGH
Network
|
lenovo
|
accelerator_application
|
UpdateAgent in Lenovo Accelerator Application allows man-in-the-middle attackers to execute arbitrary code by spoofing an update response from susapi.lenovomm.com.
|
CWE-20
Improper Input Validation
|
CVE-2016-3944
|
2024-11-21 11:50 |
2016-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266053
|
7.8 |
HIGH
Local
|
docker linuxfoundation opensuse
|
docker runc opensuse
|
libcontainer/user/user.go in runC before 0.1.0, as used in Docker before 1.11.2, improperly treats a numeric UID as a potential username, which allows local users to gain privileges via a numeric use…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-3697
|
2024-11-21 11:50 |
2016-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266054
|
7.8 |
HIGH
Local
|
huawei
|
mate_8_firmware
|
Buffer overflow in the Wi-Fi driver in Huawei Mate 8 NXT-AL before NXT-AL10C00B182, NXT-CL before NXT-CL00C92B182, NXT-DL before NXT-DL00C17B182, and NXT-TL before NXT-TL00C01B182 allows attackers to…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-3681
|
2024-11-21 11:50 |
2016-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266055
|
7.8 |
HIGH
Local
|
huawei
|
mate_8_firmware
|
Buffer overflow in the Wi-Fi driver in Huawei Mate 8 NXT-AL before NXT-AL10C00B182, NXT-CL before NXT-CL00C92B182, NXT-DL before NXT-DL00C17B182, and NXT-TL before NXT-TL00C01B182 allows attackers to…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-3680
|
2024-11-21 11:50 |
2016-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266056
|
7.4 |
HIGH
Network
|
trend_micro
|
mobile_security
|
Trend Micro Mobile Security for iOS before 3.2.1188 does not verify the X.509 certificate of the mobile application login server, which allows man-in-the-middle attackers to spoof this server and obt…
|
CWE-200
Information Exposure
|
CVE-2016-3664
|
2024-11-21 11:50 |
2016-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266057
|
5.3 |
MEDIUM
Network
|
haxx
|
curl
|
The (1) mbed_connect_step1 function in lib/vtls/mbedtls.c and (2) polarssl_connect_step1 function in lib/vtls/polarssl.c in cURL and libcurl before 7.49.0, when using SSLv3 or making a TLS connection…
|
CWE-20
Improper Input Validation
|
CVE-2016-3739
|
2024-11-21 11:50 |
2016-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266058
|
8.8 |
HIGH
Network
|
theforeman
|
foreman
|
Eval injection vulnerability in tftp_api.rb in the TFTP module in the Smart-Proxy in Foreman before 1.10.4 and 1.11.x before 1.11.2 allows remote attackers to execute arbitrary code via the PXE templ…
|
CWE-284
Improper Access Control
|
CVE-2016-3728
|
2024-11-21 11:50 |
2016-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266059
|
8.1 |
HIGH
Network
|
safemode_project
|
safemode
|
The Safemode gem before 1.2.4 for Ruby, when initialized with a delegate object that is a Rails controller, allows context-dependent attackers to obtain sensitive information via the inspect method.
|
CWE-264 CWE-200
Permissions, Privileges, and Access Controls Information Exposure
|
CVE-2016-3693
|
2024-11-21 11:50 |
2016-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266060
|
4.3 |
MEDIUM
Network
|
jenkins redhat
|
jenkins openshift
|
The API URL computer/(master)/api/xml in Jenkins before 2.3 and LTS before 1.651.2 allows remote authenticated users with extended read permission for the master node to obtain sensitive information …
|
CWE-200
Information Exposure
|
CVE-2016-3727
|
2024-11-21 11:50 |
2016-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|