|
266421
|
8.8 |
HIGH
Network
|
microsoft
|
edge
|
The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-3199
|
2024-11-21 11:49 |
2016-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266422
|
6.5 |
MEDIUM
Network
|
microsoft
|
edge
|
Microsoft Edge allows remote attackers to bypass the Content Security Policy (CSP) protection mechanism via a crafted document, aka "Microsoft Edge Security Feature Bypass."
|
CWE-254
7PK - Security Features
|
CVE-2016-3198
|
2024-11-21 11:49 |
2016-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266423
|
6.5 |
MEDIUM
Network
|
apache
|
cloudstack
|
Apache CloudStack 4.5.x before 4.5.2.1, 4.6.x before 4.6.2.1, 4.7.x before 4.7.1.1, and 4.8.x before 4.8.0.1, when SAML-based authentication is enabled and used, allow remote attackers to bypass auth…
|
CWE-287 CWE-254
Improper Authentication 7PK - Security Features
|
CVE-2016-3085
|
2024-11-21 11:49 |
2016-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266424
|
5.3 |
MEDIUM
Network
|
ognl_project apache
|
ognl struts
|
Apache Struts 2.0.0 through 2.3.24.1 does not properly cache method references when used with OGNL before 3.0.12, which allows remote attackers to cause a denial of service (block access to a web sit…
|
CWE-20
Improper Input Validation
|
CVE-2016-3093
|
2024-11-21 11:49 |
2016-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266425
|
9.8 |
CRITICAL
Network
|
apache
|
struts
|
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via vectors related to an ! (ex…
|
CWE-20
Improper Input Validation
|
CVE-2016-3087
|
2024-11-21 11:49 |
2016-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266426
|
8.8 |
HIGH
Network
|
katello redhat
|
katello satellite
|
Multiple SQL injection vulnerabilities in the scoped_search function in app/controllers/katello/api/v2/api_controller.rb in Katello allow remote authenticated users to execute arbitrary SQL commands …
|
CWE-89
SQL Injection
|
CVE-2016-3072
|
2024-11-21 11:49 |
2016-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266427
|
7.8 |
HIGH
Local
|
fedoraproject redhat
|
fedora ansible
|
The create_script function in the lxc_container module in Ansible before 1.9.6-1 and 2.x before 2.0.2.0 allows local users to write to arbitrary files or gain privileges via a symlink attack on (1) /…
|
CWE-59
Link Following
|
CVE-2016-3096
|
2024-11-21 11:49 |
2016-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266428
|
5.9 |
MEDIUM
Network
|
apache
|
qpid_broker-j
|
PlainSaslServer.java in Apache Qpid Java before 6.0.3, when the broker is configured to allow plaintext passwords, allows remote attackers to cause a denial of service (broker termination) via a craf…
|
CWE-287 CWE-20
Improper Authentication Improper Input Validation
|
CVE-2016-3094
|
2024-11-21 11:49 |
2016-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266429
|
7.5 |
HIGH
Network
|
opensuse gnu fedoraproject canonical
|
opensuse glibc fedora ubuntu_linux
|
Stack-based buffer overflow in the nss_dns implementation of the getnetbyname function in GNU C Library (aka glibc) before 2.24 allows context-dependent attackers to cause a denial of service (stack …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-3075
|
2024-11-21 11:49 |
2016-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266430
|
7.1 |
HIGH
Local
|
php
|
php
|
The make_http_soap_request function in ext/soap/php_http.c in PHP before 5.4.44, 5.5.x before 5.5.28, 5.6.x before 5.6.12, and 7.x before 7.0.4 allows remote attackers to obtain sensitive information…
|
CWE-20
Improper Input Validation
|
CVE-2016-3185
|
2024-11-21 11:49 |
2016-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|