|
266071
|
6.5 |
MEDIUM
Network
|
kallithea
|
kallithea
|
Kallithea before 0.3.2 allows remote authenticated users to edit or delete open pull requests or delete comments by leveraging read access.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-3114
|
2024-11-21 11:49 |
2017-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266072
|
5.5 |
MEDIUM
Local
|
python
|
pillow
|
Heap-based buffer overflow in the j2k_encode_entry function in Pillow 2.5.0 through 3.1.1 allows remote attackers to cause a denial of service (memory corruption) via a crafted Jpeg2000 file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-3076
|
2024-11-21 11:49 |
2017-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266073
|
9.8 |
CRITICAL
Network
|
shopware
|
shopware
|
The backend/Login/load/ script in Shopware before 5.1.5 allows remote attackers to execute arbitrary code.
|
CWE-20
Improper Input Validation
|
CVE-2016-3109
|
2024-11-21 11:49 |
2017-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266074
|
9.8 |
CRITICAL
Network
|
cygwin
|
cygwin
|
Cygwin before 2.5.0 does not properly handle updating permissions when changing users, which allows attackers to gain privileges.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-3067
|
2024-11-21 11:49 |
2017-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266075
|
5.4 |
MEDIUM
Network
|
ibm
|
cognos_business_intelligence
|
IBM Cognos TM1 10.1 and 10.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potential…
|
CWE-79
Cross-site Scripting
|
CVE-2016-3038
|
2024-11-21 11:49 |
2017-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266076
|
5.7 |
MEDIUM
Network
|
ibm
|
cognos_business_intelligence
|
IBM Cognos TM1 10.1 and 10.2 provides a service to return the victim's password with a valid session key. An authenticated attacker with user interaction could obtain this sensitive information. IBM …
|
CWE-200
Information Exposure
|
CVE-2016-3037
|
2024-11-21 11:49 |
2017-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266077
|
7.5 |
HIGH
Network
|
ibm
|
cognos_business_intelligence
|
IBM Cognos TM1 10.1 and 10.2 is vulnerable to a denial of service, caused by a stack-based buffer overflow when parsing packets. A remote attacker could exploit this vulnerability to cause a denial o…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-3036
|
2024-11-21 11:49 |
2017-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266078
|
7.5 |
HIGH
Network
|
mongodb
|
mongodb
|
mongod in MongoDB 2.6, when using 2.4-style users, and 2.4 allow remote attackers to cause a denial of service (memory consumption and process termination) by leveraging in-memory database representa…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2016-3104
|
2024-11-21 11:49 |
2017-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266079
|
5.3 |
MEDIUM
Network
|
pulpproject
|
pulp
|
Pulp before 2.8.3 creates a temporary directory during CA key generation in an insecure manner.
|
CWE-362
Race Condition
|
CVE-2016-3106
|
2024-11-21 11:49 |
2017-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266080
|
5.4 |
MEDIUM
Network
|
ibm
|
cognos_analytics
|
IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially …
|
CWE-79
Cross-site Scripting
|
CVE-2016-3031
|
2024-11-21 11:49 |
2017-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|