|
266601
|
6.1 |
MEDIUM
Network
|
ibm
|
websphere_commerce
|
Cross-site scripting (XSS) vulnerability in IBM WebSphere Commerce 6.0 through 6.0.0.11, 7.0 before 7.0.0.9 cumulative iFix 3, and 8.0 before 8.0.0.5 allows remote attackers to inject arbitrary web s…
|
CWE-79
Cross-site Scripting
|
CVE-2016-2862
|
2024-11-21 11:48 |
2016-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266602
|
5.3 |
MEDIUM
Network
|
ibm
|
qradar_security_information_and_event_manager security_qradar_incident_forensics
|
Directory traversal vulnerability in IBM Security QRadar SIEM 7.2.x before 7.2.7 and QRadar Incident Forensics 7.2.x before 7.2.7 allows remote attackers to read arbitrary files via a crafted URL.
|
CWE-22
Path Traversal
|
CVE-2016-2872
|
2024-11-21 11:48 |
2016-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266603
|
2.7 |
LOW
Network
|
ibm
|
websphere_datapower_xc10_appliance_firmware
|
Buffer overflow in the CLI on IBM WebSphere DataPower XC10 appliances 2.1 and 2.5 allows remote authenticated users to cause a denial of service via unspecified vectors.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-2870
|
2024-11-21 11:48 |
2016-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266604
|
2.7 |
LOW
Network
|
ibm
|
qradar_security_information_and_event_manager
|
IBM Security QRadar SIEM 7.2.x before 7.2.7 allows remote authenticated administrators to read arbitrary files via XML data containing an external entity declaration in conjunction with an entity ref…
|
NVD-CWE-Other
|
CVE-2016-2868
|
2024-11-21 11:48 |
2016-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266605
|
7.0 |
HIGH
Local
|
ibm
|
streams infosphere_streams
|
IBM InfoSphere Streams before 4.0.1.2 and IBM Streams before 4.1.1.1 do not properly implement the runAsUser feature, which allows local users to obtain root group privileges via unspecified vectors.
|
CWE-254
7PK - Security Features
|
CVE-2016-2867
|
2024-11-21 11:48 |
2016-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266606
|
3.7 |
LOW
Network
|
ibm
|
websphere_extreme_scale
|
IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3, 7.1.1 before 7.1.1.1, 8.5 before 8.5.0.3, and 8.6 before 8.6.0.8 does not properly encrypt data, which makes it easier for remote attackers to obtain…
|
CWE-200
Information Exposure
|
CVE-2016-2861
|
2024-11-21 11:48 |
2016-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266607
|
7.8 |
HIGH
Local
|
symantec
|
mail_security_for_microsoft_exchange norton_power_eraser protection_engine endpoint_protection message_gateway norton_360 norton_antivirus norton_internet_security norton_secu…
|
The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SE…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-2211
|
2024-11-21 11:48 |
2016-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266608
|
7.3 |
HIGH
Local
|
symantec
|
mail_security_for_microsoft_exchange norton_power_eraser protection_engine endpoint_protection message_gateway norton_360 norton_antivirus norton_internet_security norton_secu…
|
Buffer overflow in Dec2LHA.dll in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-2210
|
2024-11-21 11:48 |
2016-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266609
|
7.3 |
HIGH
Local
|
symantec
|
mail_security_for_microsoft_exchange norton_power_eraser protection_engine endpoint_protection message_gateway norton_360 norton_antivirus norton_internet_security norton_secu…
|
Buffer overflow in Dec2SS.dll in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway;…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-2209
|
2024-11-21 11:48 |
2016-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266610
|
8.4 |
HIGH
Local
|
symantec
|
mail_security_for_microsoft_exchange norton_power_eraser protection_engine endpoint_protection message_gateway norton_360 norton_antivirus norton_internet_security norton_secu…
|
The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SE…
|
CWE-20
Improper Input Validation
|
CVE-2016-2207
|
2024-11-21 11:48 |
2016-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|