|
266231
|
5.4 |
MEDIUM
Network
|
ibm
|
connections
|
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or H…
|
CWE-79
Cross-site Scripting
|
CVE-2016-3001
|
2024-11-21 11:49 |
2016-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266232
|
4.3 |
MEDIUM
Network
|
ibm
|
connections
|
The help service in IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to cause a denial of service (service degradation) via a crafted URL.
|
CWE-20
Improper Input Validation
|
CVE-2016-3000
|
2024-11-21 11:49 |
2016-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266233
|
6.5 |
MEDIUM
Network
|
ibm
|
connections
|
IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to obtain sensitive information via an unspecified brute-force attack.
|
CWE-200
Information Exposure
|
CVE-2016-2999
|
2024-11-21 11:49 |
2016-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266234
|
7.8 |
HIGH
Local
|
microsoft
|
excel excel_viewer office_compatibility_pack
|
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, and Excel Viewer allow remote attackers to execute arbitrary code via a crafted…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-3381
|
2024-11-21 11:49 |
2016-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266235
|
6.1 |
MEDIUM
Network
|
microsoft
|
exchange_server
|
Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2016 Cumulative Update 1 and 2 allows remote attackers to inject arbitrary web script or HTML via a meeting-invitation request, a…
|
CWE-79
Cross-site Scripting
|
CVE-2016-3379
|
2024-11-21 11:49 |
2016-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266236
|
7.4 |
HIGH
Network
|
microsoft
|
exchange_server
|
Open redirect vulnerability in Microsoft Exchange Server 2013 SP1, 2013 Cumulative Update 12, 2013 Cumulative Update 13, 2016 Cumulative Update 1, and 2016 Cumulative Update 2 allows remote attackers…
|
CWE-20
Improper Input Validation
|
CVE-2016-3378
|
2024-11-21 11:49 |
2016-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266237
|
7.5 |
HIGH
Network
|
microsoft
|
edge
|
The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-3377
|
2024-11-21 11:49 |
2016-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266238
|
7.5 |
HIGH
Network
|
microsoft
|
windows_rt_8.1 internet_explorer windows_server_2012 windows_7 windows_10 windows_8.1 windows_server_2008 windows_vista
|
The OLE Automation mechanism and VBScript scripting engine in Microsoft Internet Explorer 9 through 11, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Serv…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-3375
|
2024-11-21 11:49 |
2016-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266239
|
6.5 |
MEDIUM
Network
|
microsoft
|
windows_rt_8.1 windows_server_2012 windows_10 edge windows_8.1
|
The PDF library in Microsoft Edge, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information via a craf…
|
CWE-200
Information Exposure
|
CVE-2016-3374
|
2024-11-21 11:49 |
2016-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266240
|
5.5 |
MEDIUM
Local
|
microsoft
|
windows_rt_8.1 windows_server_2012 windows_7 windows_10 windows_8.1 windows_server_2008 windows_vista
|
The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 doe…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-3373
|
2024-11-21 11:49 |
2016-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|