|
266691
|
2.7 |
LOW
Network
|
ibm
|
qradar_security_information_and_event_manager
|
IBM Security QRadar SIEM 7.2.x before 7.2.7 allows remote authenticated administrators to read arbitrary files via XML data containing an external entity declaration in conjunction with an entity ref…
|
NVD-CWE-Other
|
CVE-2016-2868
|
2024-11-21 11:48 |
2016-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266692
|
7.0 |
HIGH
Local
|
ibm
|
streams infosphere_streams
|
IBM InfoSphere Streams before 4.0.1.2 and IBM Streams before 4.1.1.1 do not properly implement the runAsUser feature, which allows local users to obtain root group privileges via unspecified vectors.
|
CWE-254
7PK - Security Features
|
CVE-2016-2867
|
2024-11-21 11:48 |
2016-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266693
|
3.7 |
LOW
Network
|
ibm
|
websphere_extreme_scale
|
IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3, 7.1.1 before 7.1.1.1, 8.5 before 8.5.0.3, and 8.6 before 8.6.0.8 does not properly encrypt data, which makes it easier for remote attackers to obtain…
|
CWE-200
Information Exposure
|
CVE-2016-2861
|
2024-11-21 11:48 |
2016-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266694
|
7.8 |
HIGH
Local
|
symantec
|
mail_security_for_microsoft_exchange norton_power_eraser protection_engine endpoint_protection message_gateway norton_360 norton_antivirus norton_internet_security norton_secu…
|
The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SE…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-2211
|
2024-11-21 11:48 |
2016-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266695
|
7.3 |
HIGH
Local
|
symantec
|
mail_security_for_microsoft_exchange norton_power_eraser protection_engine endpoint_protection message_gateway norton_360 norton_antivirus norton_internet_security norton_secu…
|
Buffer overflow in Dec2LHA.dll in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-2210
|
2024-11-21 11:48 |
2016-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266696
|
7.3 |
HIGH
Local
|
symantec
|
mail_security_for_microsoft_exchange norton_power_eraser protection_engine endpoint_protection message_gateway norton_360 norton_antivirus norton_internet_security norton_secu…
|
Buffer overflow in Dec2SS.dll in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway;…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-2209
|
2024-11-21 11:48 |
2016-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266697
|
8.4 |
HIGH
Local
|
symantec
|
mail_security_for_microsoft_exchange norton_power_eraser protection_engine endpoint_protection message_gateway norton_360 norton_antivirus norton_internet_security norton_secu…
|
The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SE…
|
CWE-20
Improper Input Validation
|
CVE-2016-2207
|
2024-11-21 11:48 |
2016-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266698
|
7.5 |
HIGH
Network
|
fonality
|
hud_web fonality
|
The Chrome HUDweb plugin before 2016-05-05 for Fonality (previously trixbox Pro) 12.6 through 14.1i uses the same hardcoded private key across different customers' installations, which allows remote …
|
CWE-310 NVD-CWE-Other
Cryptographic Issues
|
CVE-2016-2364
|
2024-11-21 11:48 |
2016-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266699
|
7.8 |
HIGH
Local
|
fonality
|
fonality
|
Fonality (previously trixbox Pro) 12.6 through 14.1i before 2016-06-01 uses weak permissions for the /var/www/rpc/surun script, which allows local users to obtain root access for unspecified command …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-2363
|
2024-11-21 11:48 |
2016-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266700
|
9.8 |
CRITICAL
Network
|
fonality
|
fonality
|
Fonality (previously trixbox Pro) 12.6 through 14.1i before 2016-06-01 has a hardcoded password for the FTP account, which allows remote attackers to obtain access via a (1) FTP or (2) SSH connection.
|
NVD-CWE-Other
|
CVE-2016-2362
|
2024-11-21 11:48 |
2016-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|